Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.1% | — | Kyberna Ky2help | 13/7/2006 | 16/6/2026 | SQL injection vulnerability in Meine Links (aka My Links) in Kyberna ky2help allows remote authenticated users to execute arbitrary SQL commands via unspecified "textboxes." | |
| Modificada | Media (4.3) | 2.0% | — | Vanillasoft Helpdesk | 13/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.asp in VanillaSoft Helpdesk 2005 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Media (5.8) | 1.3% | — | Turnkey WEB Tools PHP Live Helper | 16/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in chat.php in PHP Live Helper allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Ubertec Help Center Live | 26/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in the osTicket module in Help Center Live before 2.1.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Alta (7.5) | 4.8% | — | Turnkey WEB Tools PHP Live Helper | 29/3/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php. | |
| Modificada | Alta (7.5) | 2.0% | — | Turnkey WEB Tools PHP Live Helper | 29/3/2006 | 16/6/2026 | Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by… | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Microsoft Html HelpMicrosoft Html Help Workshop | 6/2/2006 | 16/6/2026 | Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Cerberus Helpdesk | 1/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields. | |
| Modificada | Alta (7.5) | 1.1% | — | Help Desk Point Software Helpdeskpoint | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Cerberus Helpdesk | 20/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to… | |
| Modificada | Media (4.3) | 1.3% | — | Cerberus Helpdesk | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Netauctionhelp | 7/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) L, (2) sort, (3) category, (4) categoryname parameters to search.asp. | |
| Modificada | Alta (7.5) | 1.4% | — | Help Desk Reloaded Free Help DeskAI | 5/12/2005 | 16/6/2026 | Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Helpdesk Issue Manager | 30/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | EZY Helpdesk Ezyhelpdesk | 26/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Ubertec Help Center Live | 16/11/2005 | 16/6/2026 | PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability. | |
| Modificada | Media (5) | 1.5% | — | Cerberus Helpdesk | 5/11/2005 | 16/6/2026 | attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Helpdesk Software Hesk | 21/9/2005 | 16/6/2026 | Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie. | |
| Modificada | Alta (7.5) | 1.6% | — | Helpdesk Software Hesk | 8/9/2005 | 16/6/2026 | Helpdesk software Hesk 0.92 does not properly verify usernames and passwords, which allows remote attackers to bypass authentication via a direct request to admin_main.php. | |
| Modificada | Media (4.3) | 1.3% | — | Cerberus Helpdesk | 16/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php. | |
| Modificada | Media (5) | 1.5% | — | Cerberus Helpdesk | 16/6/2005 | 16/6/2026 | Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message. | |
| Modificada | Alta (7.5) | 1.3% | — | Liberum Help Desk | 2/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.asp or (2) print.asp or (3) edit parameter to register.asp. | |
| Modificada | Media (5) | 1.1% | — | Liberum Help Desk | 2/6/2005 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in castnewPost.asp in Liberum Help Desk 0.97.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Email, (2) Title, or (3) Description fields. | |
| Modificada | Media (4.3) | 2.7% | 💥 Exploit | Ubertec Help Center Live | 19/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message field of a chat request, or (4) the message body when opening a trouble ticket. | |
| Modificada | Media (6.5) | 2.9% | 💥 Exploit | Helpcenterlive Help Center Live | 19/5/2005 | 16/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php. |