Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.2%—Qnap Helpdesk11/6/202117/6/2026
An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.4.
ModificadaCrítica (9.8)3.0%—Qnap Helpdesk3/2/202117/6/2026
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
AnalizadaCrítica (9.8)2.0%⚠ Explotación activaQnap Helpdesk3/2/202117/6/2026
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to…
ModificadaMedia (6.5)1.7%—Solarwinds Webhelpdesk21/12/202017/6/2026
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
ModificadaMedia (5.4)1.5%—Solarwinds Webhelpdesk18/12/202017/6/2026
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
ModificadaMedia (5.4)1.7%—Solarwinds Webhelpdesk18/12/202017/6/2026
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
ModificadaAlta (7.5)1.3%—Evolutionscript Helpdeskz12/10/202017/6/2026
An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
ModificadaMedia (6.5)0.30%—Qnap Helpdesk11/9/202017/6/2026
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
ModificadaMedia (6.5)0.76%—Qnap Helpdesk11/9/202017/6/2026
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
ModificadaMedia (5.9)0.32%—Qnap Helpdesk11/9/202017/6/2026
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and…
ModificadaMedia (6.5)0.74%—Qnap Helpdesk1/7/202017/6/2026
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in Helpdesk 3.0.1 and later versions.
ModificadaCrítica (9.1)2.1%—Inetsoftware Clear ReportsInetsoftware HelpdeskInetsoftware Pdfc7/5/202017/6/2026
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.
ModificadaAlta (7.8)1.3%—Solarwinds Webhelpdesk27/4/202017/6/2026
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
ModificadaAlta (7.5)1.3%—Qnap Helpdesk4/12/201917/6/2026
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.
ModificadaAlta (7.2)4.8%💥 PoCJitbit Helpdesk9/8/201917/6/2026
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The…
ModificadaCrítica (9.8)2.3%—Qnap Helpdesk13/8/201817/6/2026
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.
ModificadaAlta (7.5)2.6%💥 ExploitQnap QTS Helpdesk6/10/201717/6/2026
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.
ModificadaMedia (5.4)0.60%—Mirasvit Helpdesk MX21/9/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the administrative interface in Mirasvit Helpdesk MX before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) customer name or (2) subject in a ticket.
ModificadaAlta (8)1.4%—Mirasvit Helpdesk MX21/9/201717/6/2026
Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter uploaded files.
ModificadaAlta (8.1)7.4%💥 ExploitHelpdeskpro Helpdesk PRO20/9/201717/6/2026
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.
ModificadaAlta (7.5)57%💥 ExploitHelpdesk PRO Project Helpdesk PRO20/9/201717/6/2026
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.
ModificadaCrítica (9.8)4.2%💥 ExploitHelpdesk PRO Project Helpdesk PRO20/9/201717/6/2026
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter.
ModificadaMedia (5.4)2.9%💥 ExploitHelpdesk PRO Project Helpdesk PRO20/9/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message.
ModificadaMedia (5.3)9.6%💥 ExploitHelpdesk PRO Project Helpdesk PRO18/8/201717/6/2026
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}.
ModificadaAlta (8)2.2%💥 ExploitLadybirdweb Faveo Helpdesk6/4/201717/6/2026
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
Orbitaley — Vulnerabilidades