Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Ubertec Help Center Live | 19/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter to (3) download.php or (4) chat_download.php, (5) status parameter to icon.php, TICKET_tid parameter to (6) index.php… | |
| Modificada | Media (6.8) | 1.9% | — | Ubertec Help Center Live | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Leigh Business Enterprises WEB Helpdesk | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Wehelpbus | 31/12/2004 | 16/6/2026 | Unknown vulnerability in WeHelpBUS 0.1 allows remote attackers to execute arbitrary shell commands via the query string. | |
| Modificada | Media (4.3) | 1.4% | — | Ubertec Help Center Live | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Crafty Syntax Live Help | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the name field of a livehelp or chat session. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Layton Technology Helpbox | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in export_data.asp, (4) the sys_analgroup parameter… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Netsupport DNA Helpdesk | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter. | |
| Modificada | Media (6.4) | 1.5% | — | Ubertec Help Center Live | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php. | |
| Modificada | Media (5) | 5.4% | 💥 Exploit | Polar Software Helpdesk | 31/12/2004 | 16/6/2026 | Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Oneorzero Helpdesk | 9/6/2003 | 16/6/2026 | SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter. | |
| Modificada | Alta (10) | 8.1% | 💥 Exploit | Oneorzero Helpdesk | 9/6/2003 | 16/6/2026 | one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Luis Bernardo Myhelpdesk | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via a (1) Title or (2) Description when a new ticket is created by a support assistant, via the "id" parameter to the index.php script with the (3) tickettime, (4)… | |
| Modificada | Media (6.4) | 1.2% | 💥 Exploit | Luis Bernardo Myhelpdesk | 4/10/2002 | 16/6/2026 | SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog. | |
| Modificada | Alta (7.5) | 26% | 💥 Exploit | Microsoft Windows HelpMicrosoft Windows 2000 | 12/8/2002 | 16/6/2026 | Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter. | |
| Modificada | Alta (7.5) | 7.4% | 💥 Exploit | Lucent VitalanalysisLucent VitaleventLucent VitalhelpLucent Vitalnet+1 | 29/5/2002 | 16/6/2026 | Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user. |