Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.18% | — | Uvnc Pchelpwarev2 | 21/3/2026 | 17/6/2026 | PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying a malformed image file. Attackers can trigger the vulnerability through the Create SC feature by selecting a crafted BMP file with an oversized buffer, causing the application to crash. | |
| Aplazada | Alta (7.2) | 0.42% | — | Themehelper Checkout Field EditorAI | 11/3/2026 | 17/6/2026 | The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and checkboxgroup field values submitted through the WooCommerce Block Checkout Store API in all versions up to, and including, 2.1.7. This is due to the… | |
| Aplazada | Alta (7.5) | 1.3% | — | Jshelpdesk JS Help DeskAI | 4/3/2026 | 17/6/2026 | The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied values and lack of… | |
| Analizada | Media (4.9) | 0.34% | — | Livehelperchat Live Helper Chat | 26/2/2026 | 17/6/2026 | Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreClassChat::hasAccessToRead()`, allowing operators to act on chats… | |
| Aplazada | Alta (8.5) | 0.22% | — | Joomsky JS Help DeskAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Elextensions Elex Wordpress Helpdesk Customer Support Ticket SystemAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through <= 3.3.5. | |
| Aplazada | Alta (8.2) | 0.28% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.8. | |
| Aplazada | Media (5.3) | 0.30% | — | Elex Wordpress Helpdesk Customer Ticketing SystemAI | 5/2/2026 | 17/6/2026 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This is due to missing capability checks on the eh_crm_ticket_general function combined with a shared nonce that is exposed to low-privileged users. This… | |
| Aplazada | Media (5.1) | 0.17% | — | Maian Support HelpdeskAI | 3/2/2026 | 17/6/2026 | Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system. | |
| Analizada | Alta (7.8) | 0.17% | — | Avanquest PC Helpsoft Driver Updater | 3/2/2026 | 17/6/2026 | Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component. | |
| Aplazada | Media (6.9) | 0.28% | — | Livehelperchat Live Helper ChatAI | 28/1/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the… | |
| Analizada | Crítica (9.8) | 61% | — | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk. | |
| Modificada | Crítica (9.8) | 68% | — | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | |
| Modificada | Crítica (9.8) | 52% | — | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication. | |
| Analizada | Crítica (9.8) | 84% | ⚠ Explotación activa | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | |
| Analizada | Alta (7.5) | 0.59% | — | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions. | |
| Analizada | Crítica (9.8) | 74% | ⚠ Explotación activa | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality. | |
| Aplazada | Crítica (10) | 0.37% | — | Ttttupup WxhelperAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files mongoose.C. This issue affects wxhelper: through 3.9.10.19-v1. | |
| Aplazada | Media (6.4) | 0.24% | — | NK Themes HelperAI | 8/1/2026 | 5/10/2026 | Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request Forgery.This issue affects nK Themes Helper: from n/a through <= 1.7.9. | |
| Aplazada | Media (4.3) | 0.16% | — | Helpdesk Contact FormAI | 7/1/2026 | 17/6/2026 | The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on the handle_query_args() function. This makes it possible for unauthenticated attackers to update the plugin's license ID and… | |
| Aplazada | Media (5.3) | 0.22% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 23/12/2025 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.9. | |
| Aplazada | Alta (7.2) | 0.23% | — | Elex Wordpress Helpdesk Customer Ticketing SystemAI | 21/12/2025 | 28/9/2026 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Media (6.6) | 0.10% | — | Netun Helpflash IOT Firmware | 17/12/2025 | 17/6/2026 | The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signatures. An attacker with brief physical access can activate OTA mode (8-second… | |
| Analizada | Alta (8.6) | 0.56% | — | Frappe Helpdesk | 9/12/2025 | 17/6/2026 | SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0. | |
| Analizada | Media (5.1) | 0.17% | — | Acustica-audio Aquarius Helpertool | 3/12/2025 | 17/6/2026 | The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local process without validating the client's identity, and its authorization logic incorrectly calls AuthorizationCopyRights with a NULL… |