Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

516 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%💥 ExploitUbertec Help Center Live19/5/200516/6/2026
Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter to (3) download.php or (4) chat_download.php, (5) status parameter to icon.php, TICKET_tid parameter to (6) index.php…
ModificadaMedia (6.8)1.9%—Ubertec Help Center Live31/12/200416/6/2026
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.
ModificadaAlta (7.5)1.4%💥 ExploitLeigh Business Enterprises WEB Helpdesk31/12/200416/6/2026
SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.8%—Wehelpbus31/12/200416/6/2026
Unknown vulnerability in WeHelpBUS 0.1 allows remote attackers to execute arbitrary shell commands via the query string.
ModificadaMedia (4.3)1.4%—Ubertec Help Center Live31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.
ModificadaMedia (4.3)2.0%💥 ExploitCrafty Syntax Live Help31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the name field of a livehelp or chat session.
ModificadaAlta (7.5)2.3%💥 ExploitLayton Technology Helpbox31/12/200416/6/2026
Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in export_data.asp, (4) the sys_analgroup parameter…
ModificadaAlta (7.5)1.0%💥 ExploitNetsupport DNA Helpdesk31/12/200416/6/2026
SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter.
ModificadaMedia (6.4)1.5%—Ubertec Help Center Live31/12/200416/6/2026
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php.
ModificadaMedia (5)5.4%💥 ExploitPolar Software Helpdesk31/12/200416/6/2026
Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.
ModificadaMedia (5)2.5%💥 ExploitOneorzero Helpdesk9/6/200316/6/2026
SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.
ModificadaAlta (10)8.1%💥 ExploitOneorzero Helpdesk9/6/200316/6/2026
one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.
ModificadaAlta (7.5)3.1%💥 ExploitLuis Bernardo Myhelpdesk4/10/200216/6/2026
Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via a (1) Title or (2) Description when a new ticket is created by a support assistant, via the "id" parameter to the index.php script with the (3) tickettime, (4)…
ModificadaMedia (6.4)1.2%💥 ExploitLuis Bernardo Myhelpdesk4/10/200216/6/2026
SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog.
ModificadaAlta (7.5)26%💥 ExploitMicrosoft Windows HelpMicrosoft Windows 200012/8/200216/6/2026
Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter.
ModificadaAlta (7.5)7.4%💥 ExploitLucent VitalanalysisLucent VitaleventLucent VitalhelpLucent Vitalnet+129/5/200216/6/2026
Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user.
Orbitaley — Vulnerabilidades