Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
92 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.0% | 💥 Exploit | Wiselyhub JS Help Desk | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1. | |
| Modificada | Alta (8.8) | 2.0% | 💥 PoC | Spiceworks Help Desk Server | 9/11/2023 | 17/6/2026 | An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak… | |
| Modificada | Media (5.4) | 0.46% | — | Help Desk WP Project Help Desk WP | 15/5/2023 | 17/6/2026 | The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks. | |
| Modificada | Media (6.5) | 0.56% | — | Wpruby Ruby Help Desk | 2/5/2023 | 17/6/2026 | The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own. | |
| Modificada | Crítica (9.8) | 2.2% | — | Wyomind Help Desk | 8/3/2023 | 17/6/2026 | Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting. | |
| Modificada | Crítica (9.8) | 1.4% | — | Wyomind Help Desk | 8/3/2023 | 17/6/2026 | An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field. | |
| Modificada | Crítica (9) | 1.0% | — | Wyomind Help Desk | 8/3/2023 | 17/6/2026 | Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field. | |
| Modificada | Alta (8.8) | 0.26% | — | Wiselyhub JS Help Desk | 2/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions. | |
| Modificada | Media (6.1) | 0.44% | — | Sysaid Help Desk | 11/9/2022 | 17/6/2026 | SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262. | |
| Modificada | Media (6.1) | 0.44% | — | Sysaid Help Desk | 11/9/2022 | 17/6/2026 | SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258. | |
| Modificada | Media (6.1) | 0.44% | — | Sysaid Help Desk | 11/9/2022 | 17/6/2026 | SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241. | |
| Modificada | Media (6.1) | 0.44% | — | Sysaid Help Desk | 11/9/2022 | 17/6/2026 | SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579. | |
| Modificada | Media (5.3) | 0.95% | — | Solarwinds WEB Help Desk | 10/3/2022 | 17/6/2026 | Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation. | |
| Modificada | Alta (7.5) | 0.90% | — | Solarwinds WEB Help Desk | 23/12/2021 | 17/6/2026 | The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes… | |
| Modificada | Crítica (9.8) | 5.6% | 💥 PoC | Schiocco Support Board - Chat AND Help Desk | 20/9/2021 | 17/6/2026 | The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users. | |
| Modificada | Media (5.3) | 1.2% | — | Solarwinds WEB Help Desk | 26/8/2021 | 17/6/2026 | Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing… | |
| Modificada | Media (5.4) | 1.5% | — | Solarwinds WEB Help Desk | 15/1/2021 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name. | |
| Modificada | Media (5.4) | 1.3% | — | Solarwinds WEB Help Desk | 6/1/2021 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket. | |
| Modificada | Media (5.4) | 1.3% | — | Solarwinds WEB Help Desk | 4/1/2021 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field. | |
| Modificada | Media (5.4) | 1.7% | — | Solarwinds WEB Help Desk | 4/1/2021 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket. | |
| Modificada | Media (5.4) | 1.2% | — | Solarwinds Help Desk | 1/12/2020 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name. | |
| Modificada | Media (6.5) | 1.3% | — | Otrs FAQOtrs Help DeskOtrs ItsmDebian Linux+1 | 27/11/2019 | 16/6/2026 | An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified | |
| Modificada | Alta (8.8) | 0.68% | — | Joomsky JS Help Desk | 27/8/2019 | 17/6/2026 | The js-support-ticket plugin before 2.0.6 for WordPress has CSRF. | |
| Modificada | Media (5.4) | 0.80% | — | Schiocco Support Board - Chat AND Help Desk | 17/10/2018 | 17/6/2026 | In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a /wp-admin/admin-ajax.php sb_ajax_add_message action. | |
| Modificada | Media (6) | 1.8% | — | Otrs Help Desk | 19/12/2014 | 17/6/2026 | The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x before 3.3.11, and 4.0.x before 4.0.3 allows remote authenticated users to access and modify arbitrary tickets via unspecified vectors. |