Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.45% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function. | |
| Analizada | Alta (7.5) | 0.76% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function. | |
| Analizada | Alta (7.5) | 0.76% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function. | |
| Analizada | Alta (7.5) | 0.76% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function. | |
| Aplazada | Media (6.4) | 0.35% | — | Crmperks Wordpress Helpdesk IntegrationAI | 16/12/2024 | 17/6/2026 | The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'crm-perks-tickets' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied… | |
| Analizada | Media (5.4) | 0.45% | — | Ladybirdweb Faveo Helpdesk | 1/11/2024 | 17/6/2026 | An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields | |
| Aplazada | Alta (8.2) | 0.38% | — | Ladybird WEB Solution Faveo-helpdeskAI | 22/10/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file. | |
| Aplazada | Alta (7.6) | 0.47% | — | Helpdeskz Helpdesk ZAI | 23/9/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box. | |
| Analizada | Media (4.8) | 0.25% | — | Qnap Helpdesk | 6/9/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following version: Helpdesk 3.3.1 and later | |
| Aplazada | Crítica (9.8) | 38% | 💥 PoC | Jshelpdesk JS Help DeskAI | 13/8/2024 | 17/6/2026 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the… | |
| Aplazada | Alta (8.8) | 0.40% | — | PrestashopAIFmemodules HelpdeskAI | 24/6/2024 | 17/6/2026 | SQL Injection vulnerability in the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via 'Tickets::getsearchedtickets()' | |
| Aplazada | Crítica (10) | 0.51% | — | PrestashopAIFmemodules HelpdeskAI | 19/6/2024 | 17/6/2026 | In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods `HelpdeskHelpdeskModuleFrontController::submitTicket()` and `HelpdeskHelpdeskModuleFrontController::replyTicket()` allow upload of .php files on a… | |
| Modificada | Alta (7.3) | 0.30% | — | Awesomesupport Awesome Support Wordpress Helpdesk & Support | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5. | |
| Analizada | Media (6.1) | 0.29% | — | Helpdeskz | 1/3/2024 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability has been found in HelpDeskZ affecting version 2.0.2 and earlier. This vulnerability could allow an attacker to send a specially crafted JavaScript payload within the email field and partially take control of an authenticated user's browser session. | |
| Modificada | Media (5.4) | 0.47% | — | Ladybirdweb Faveo Helpdesk | 24/6/2023 | 17/6/2026 | Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the application. This occurs because the application is vulnerable to stored XSS. | |
| Modificada | Alta (8.8) | 0.47% | — | Jshelpdesk | 23/6/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in JS Help Desk js-support-ticket allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk: from n/a through 2.7.7. | |
| Modificada | Alta (8.8) | 0.80% | — | Ladybirdweb Faveo Helpdesk | 24/3/2023 | 17/6/2026 | Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection. | |
| Modificada | Media (4.8) | 0.56% | — | Helpdeskz | 13/6/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field. | |
| Modificada | Media (4.8) | 0.56% | — | Helpdeskz | 13/6/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field. | |
| Modificada | Alta (8.8) | 1.0% | — | Solarwinds Webhelpdesk | 25/3/2022 | 17/6/2026 | SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future. | |
| Modificada | Media (6.1) | 0.30% | — | Solarwinds Webhelpdesk | 27/12/2021 | 17/6/2026 | Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary… | |
| Modificada | Crítica (9.6) | 1.4% | — | Django-helpdesk Project Django-helpdesk | 1/12/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.4) | 0.80% | — | Django-helpdesk Project Django-helpdesk | 19/11/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.1) | 1.0% | — | Django-helpdesk Project Django-helpdesk | 13/11/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.1) | 0.84% | — | Faveohelpdesk Faveo | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter. |