Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.40% | — | Yohann0617 Oci-helperAI | 2/12/2025 | 3/9/2026 | A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file src/main/java/com/yohann/ocihelper/service/impl/OciServiceImpl.java of the component OCI Configuration Upload. Executing manipulation of the argument File can lead to path traversal. It is possible… | |
| Aplazada | Media (5.3) | 0.22% | — | Themeatelier Chat HelpAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chat Help: from n/a through <= 3.1.3. | |
| Aplazada | Crítica (10) | 0.45% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 6/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code Inclusion.This issue affects HAPPY: from n/a through <= 1.0.7. | |
| Aplazada | Media (6.1) | 0.16% | — | SH Contextual HelpAI | 4/11/2025 | 17/6/2026 | The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation in the sh_contextual_help_dashboard_widget() function. This makes it possible for unauthenticated attackers to update the plugin's… | |
| Aplazada | Alta (7.8) | 0.16% | — | Trimble Sketchup DesktopAITrimble Sketchup WebhelperAI | 31/10/2025 | 5/7/2026 | DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe. | |
| Modificada | Alta (7.5) | 0.52% | — | Algoliasearch-helper | 27/9/2025 | 17/6/2026 | Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extreme edge-case" that the resulting error is caught, code injected… | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa | Solarwinds WEB Help Desk | 23/9/2025 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of… | |
| Aplazada | Media (5.3) | 0.29% | — | Essekia Helpie FAQAI | 22/9/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Essekia Helpie FAQ helpie-faq allows Retrieve Embedded Sensitive Data.This issue affects Helpie FAQ: from n/a through <= 1.45. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI | 22/9/2025 | 1/10/2026 | Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.1. | |
| Aplazada | Media (6.5) | 0.23% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.6. | |
| Aplazada | Alta (8.1) | 0.71% | — | Wordpress Helpdesk IntegrationAI | 5/9/2025 | 25/9/2026 | The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.8.10 via the portal_type parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP… | |
| Analizada | Crítica (9.8) | 39% | — | Solarwinds WEB Help Desk | 1/9/2025 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI… | |
| Analizada | Media (6.1) | 0.34% | — | Helpy.io Helpy | 26/8/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic Ticket funtion. | |
| Analizada | Media (6.5) | 0.27% | — | Solarwinds WEB Help Desk | 29/7/2025 | 17/6/2026 | SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files. | |
| Analizada | Alta (8.8) | 0.17% | — | Simple-help Simplehelp | 25/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11. | |
| Analizada | Alta (8.8) | 0.44% | — | Simple-help Simplehelp | 25/7/2025 | 17/6/2026 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12. | |
| Analizada | Media (6.5) | 1.5% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter. | |
| Analizada | Media (5.4) | 0.92% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter. | |
| Analizada | Media (5.4) | 0.92% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | |
| Analizada | Media (5.4) | 0.92% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | |
| Analizada | Media (5.4) | 0.95% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists. | |
| Analizada | Media (5.4) | 0.97% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter. | |
| Aplazada | Baja (2) | 0.28% | — | Livehelperchat LHC PHP ResqueAI | 11/7/2025 | 17/6/2026 | A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It has been classified as problematic. This affects an unknown part of the file /site_admin/lhcphpresque/list/ of the component List Handler. The manipulation of the argument queue name leads to cross… | |
| Analizada | Media (4.4) | 0.21% | — | Django-helpdesk Project Django-helpdesk | 31/5/2025 | 17/6/2026 | django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py. | |
| Analizada | Media (6.1) | 0.37% | — | Wphelpline Allow SVG | 15/5/2025 | 17/6/2026 | The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. |