Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.2% | — | Qnap Helpdesk | 11/6/2021 | 17/6/2026 | An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.4. | |
| Modificada | Crítica (9.8) | 3.0% | — | Qnap Helpdesk | 3/2/2021 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3. | |
| Analizada | Crítica (9.8) | 2.0% | ⚠ Explotación activa | Qnap Helpdesk | 3/2/2021 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to… | |
| Modificada | Media (6.5) | 1.7% | — | Solarwinds Webhelpdesk | 21/12/2020 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket. | |
| Modificada | Media (5.4) | 1.5% | — | Solarwinds Webhelpdesk | 18/12/2020 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. | |
| Modificada | Media (5.4) | 1.7% | — | Solarwinds Webhelpdesk | 18/12/2020 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. | |
| Modificada | Alta (7.5) | 1.3% | — | Evolutionscript Helpdeskz | 12/10/2020 | 17/6/2026 | An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Media (6.5) | 0.30% | — | Qnap Helpdesk | 11/9/2020 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later. | |
| Modificada | Media (6.5) | 0.76% | — | Qnap Helpdesk | 11/9/2020 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later. | |
| Modificada | Media (5.9) | 0.32% | — | Qnap Helpdesk | 11/9/2020 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and… | |
| Modificada | Media (6.5) | 0.74% | — | Qnap Helpdesk | 1/7/2020 | 17/6/2026 | This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in Helpdesk 3.0.1 and later versions. | |
| Modificada | Crítica (9.1) | 2.1% | — | Inetsoftware Clear ReportsInetsoftware HelpdeskInetsoftware Pdfc | 7/5/2020 | 17/6/2026 | The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal. | |
| Modificada | Alta (7.8) | 1.3% | — | Solarwinds Webhelpdesk | 27/4/2020 | 17/6/2026 | Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user. | |
| Modificada | Alta (7.5) | 1.3% | — | Qnap Helpdesk | 4/12/2019 | 17/6/2026 | This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions. | |
| Modificada | Alta (7.2) | 4.8% | 💥 PoC | Jitbit Helpdesk | 9/8/2019 | 17/6/2026 | Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The… | |
| Modificada | Crítica (9.8) | 2.3% | — | Qnap Helpdesk | 13/8/2018 | 17/6/2026 | Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Qnap QTS Helpdesk | 6/10/2017 | 17/6/2026 | QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack. | |
| Modificada | Media (5.4) | 0.60% | — | Mirasvit Helpdesk MX | 21/9/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative interface in Mirasvit Helpdesk MX before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) customer name or (2) subject in a ticket. | |
| Modificada | Alta (8) | 1.4% | — | Mirasvit Helpdesk MX | 21/9/2017 | 17/6/2026 | Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter uploaded files. | |
| Modificada | Alta (8.1) | 7.4% | 💥 Exploit | Helpdeskpro Helpdesk PRO | 20/9/2017 | 17/6/2026 | The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task. | |
| Modificada | Alta (7.5) | 57% | 💥 Exploit | Helpdesk PRO Project Helpdesk PRO | 20/9/2017 | 17/6/2026 | Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task. | |
| Modificada | Crítica (9.8) | 4.2% | 💥 Exploit | Helpdesk PRO Project Helpdesk PRO | 20/9/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter. | |
| Modificada | Media (5.4) | 2.9% | 💥 Exploit | Helpdesk PRO Project Helpdesk PRO | 20/9/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message. | |
| Modificada | Media (5.3) | 9.6% | 💥 Exploit | Helpdesk PRO Project Helpdesk PRO | 18/8/2017 | 17/6/2026 | The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}. | |
| Modificada | Alta (8) | 2.2% | 💥 Exploit | Ladybirdweb Faveo Helpdesk | 6/4/2017 | 17/6/2026 | public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. |