Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.45%—Zucchetti Helpdeskadvanced13/1/202517/6/2026
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function.
AnalizadaAlta (7.5)0.76%—Zucchetti Helpdeskadvanced13/1/202517/6/2026
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.
AnalizadaAlta (7.5)0.76%—Zucchetti Helpdeskadvanced13/1/202517/6/2026
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.
AnalizadaAlta (7.5)0.76%—Zucchetti Helpdeskadvanced13/1/202517/6/2026
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.
AplazadaMedia (6.4)0.35%—Crmperks Wordpress Helpdesk IntegrationAI16/12/202417/6/2026
The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'crm-perks-tickets' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied…
AnalizadaMedia (5.4)0.45%—Ladybirdweb Faveo Helpdesk1/11/202417/6/2026
An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields
AplazadaAlta (8.2)0.38%—Ladybird WEB Solution Faveo-helpdeskAI22/10/202417/6/2026
An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file.
AplazadaAlta (7.6)0.47%—Helpdeskz Helpdesk ZAI23/9/202417/6/2026
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box.
AnalizadaMedia (4.8)0.25%—Qnap Helpdesk6/9/202417/6/2026
A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following version: Helpdesk 3.3.1 and later
AplazadaCrítica (9.8)38%💥 PoCJshelpdesk JS Help DeskAI13/8/202417/6/2026
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the…
AplazadaAlta (8.8)0.40%—PrestashopAIFmemodules HelpdeskAI24/6/202417/6/2026
SQL Injection vulnerability in the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via 'Tickets::getsearchedtickets()'
AplazadaCrítica (10)0.51%—PrestashopAIFmemodules HelpdeskAI19/6/202417/6/2026
In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods `HelpdeskHelpdeskModuleFrontController::submitTicket()` and `HelpdeskHelpdeskModuleFrontController::replyTicket()` allow upload of .php files on a…
ModificadaAlta (7.3)0.30%—Awesomesupport Awesome Support Wordpress Helpdesk & Support12/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.
AnalizadaMedia (6.1)0.29%—Helpdeskz1/3/202417/6/2026
A Cross-Site Scripting (XSS) vulnerability has been found in HelpDeskZ affecting version 2.0.2 and earlier. This vulnerability could allow an attacker to send a specially crafted JavaScript payload within the email field and partially take control of an authenticated user's browser session.
ModificadaMedia (5.4)0.47%—Ladybirdweb Faveo Helpdesk24/6/202317/6/2026
Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the application. This occurs because the application is vulnerable to stored XSS.
ModificadaAlta (8.8)0.47%—Jshelpdesk23/6/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in JS Help Desk js-support-ticket allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk: from n/a through 2.7.7.
ModificadaAlta (8.8)0.80%—Ladybirdweb Faveo Helpdesk24/3/202317/6/2026
Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection.
ModificadaMedia (4.8)0.56%—Helpdeskz13/6/202217/6/2026
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
ModificadaMedia (4.8)0.56%—Helpdeskz13/6/202217/6/2026
A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
ModificadaAlta (8.8)1.0%—Solarwinds Webhelpdesk25/3/202217/6/2026
SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future.
ModificadaMedia (6.1)0.30%—Solarwinds Webhelpdesk27/12/202117/6/2026
Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary…
ModificadaCrítica (9.6)1.4%—Django-helpdesk Project Django-helpdesk1/12/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (5.4)0.80%—Django-helpdesk Project Django-helpdesk19/11/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (6.1)1.0%—Django-helpdesk Project Django-helpdesk13/11/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (6.1)0.84%—Faveohelpdesk Faveo1/10/202117/6/2026
Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter.
Orbitaley — Vulnerabilidades