Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
92 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9) | 2.5% | — | Wave Embassy Remote Administration ServerWave Embassy Remote Administration Server Help Desk | 15/7/2013 | 16/6/2026 | SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote authenticated users to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field), leading to execution of operating-system commands. | |
| Modificada | Alta (7.5) | 1.3% | — | Wave Embassy Remote Administration ServerWave Embassy Remote Administration Server Help Desk | 15/7/2013 | 16/6/2026 | SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote attackers to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field). | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | P-hd PHD Help Desk | 23/11/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to area.php; the (2) pagina, (3) sentido, (4) q_registros, and (5) orden parameters to area.php; (6) the q_registros parameter to solic_display.php; (7) the… | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Zenhelpdesk ZEN Help Desk | 27/7/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp. | |
| Modificada | Media (4.3) | 1.2% | — | Webhelpdesk WEB Help Desk | 7/4/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Web Help Desk 9.1.22 (evaluation version) allow remote attackers to inject arbitrary web script or HTML via the (1) Report Name, (2) Asset No., and (3) Full Name fields in a Models action. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | Liberum Help Desk | 4/2/2009 | 16/6/2026 | Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request. | |
| Modificada | Media (4.3) | 1.0% | — | Webhelpdesk WEB Help Desk | 27/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa. | |
| Modificada | Alta (9.3) | 6.7% | — | Componentone SizeroneSAP GUISAP TaboneServantix Tsc2 Help Desk | 8/1/2009 | 16/6/2026 | Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and… | |
| Modificada | Alta (7.5) | 1.3% | — | PHD Help Desk | 5/9/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHD Help Desk before 1.31 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | ZEN Help Desk Software ZEN Help Desk | 11/6/2007 | 16/6/2026 | Zen Help Desk 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct request for ZenHelpDesk.mdb. | |
| Modificada | Alta (7.5) | 1.3% | — | Doug Luxem Liberum Help Desk | 28/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) uid parameter to (a) inout/status.asp, (b) inout/update.asp, and (c) forgotpass.asp. NOTE: The provenance of this information is unknown; the details… | |
| Modificada | Media (6.8) | 2.9% | 💥 Exploit | ACE HelpdeskInverseflow Help DeskPmos Helpdesk | 28/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Doug Luxem Liberum Help Desk | 28/11/2006 | 16/6/2026 | SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Help Desk Point Software Helpdeskpoint | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Help Desk Reloaded Free Help DeskAI | 5/12/2005 | 16/6/2026 | Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user. | |
| Modificada | Media (5) | 1.1% | — | Liberum Help Desk | 2/6/2005 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in castnewPost.asp in Liberum Help Desk 0.97.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Email, (2) Title, or (3) Description fields. | |
| Modificada | Alta (7.5) | 1.3% | — | Liberum Help Desk | 2/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.asp or (2) print.asp or (3) edit parameter to register.asp. |