Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.21% | — | Ankur Vishwakarma WP Avcl Automation HelperAI | 24/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Ankur Vishwakarma WP AVCL Automation Helper (formerly WPFlyLeads) woozap allows Server Side Request Forgery.This issue affects WP AVCL Automation Helper (formerly WPFlyLeads): from n/a through <= 3.4. | |
| Aplazada | Alta (8.5) | 0.34% | — | Wedevs Appsero HelperAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper appsero-helper allows SQL Injection.This issue affects Appsero Helper: from n/a through <= 1.3.4. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Wpwax HelpgentAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpWax HelpGent helpgent allows Object Injection.This issue affects HelpGent: from n/a through <= 2.2.5. | |
| Aplazada | Media (6.5) | 0.30% | — | Matbao WP Helper PremiumAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Mat Bao Corporation WP Helper Premium wp-helper-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Helper Premium: from n/a through <= 4.6.1. | |
| Aplazada | Media (6.5) | 0.27% | — | Vision HelpdeskAI | 15/4/2025 | 17/6/2026 | Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed. | |
| Aplazada | Media (6.5) | 0.31% | — | Quantumcloud SEO HelpAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in QuantumCloud SEO Help seo-help allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEO Help: from n/a through <= 6.7.9. | |
| Aplazada | Media (6.8) | 0.46% | — | Quantumcloud SEO HelpAI | 9/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in QuantumCloud SEO Help seo-help allows Server Side Request Forgery.This issue affects SEO Help: from n/a through <= 6.7.9. | |
| Aplazada | Alta (7.1) | 0.29% | — | M. ALI Saleem Support Helpdesk Ticket System LiteAI | 3/4/2025 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alisaleem252 Support Helpdesk Ticket System Lite ticket-help-desk-system-lite allows Reflected XSS.This issue affects Support Helpdesk Ticket System Lite: from n/a through 4.5.2. | |
| Modificada | Alta (8.1) | 0.87% | — | Joomsky JS Help Desk | 1/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Help Desk js-support-ticket allows PHP Local File Inclusion.This issue affects JS Help Desk: from n/a through <= 2.9.2. | |
| Modificada | Crítica (10) | 0.53% | — | Joomsky JS Help Desk | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows SQL Injection.This issue affects JS Help Desk: from n/a through <= 2.9.2. | |
| Modificada | Alta (7.5) | 0.60% | — | Joomsky JS Help Desk | 1/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Traversal.This issue affects JS Help Desk: from n/a through <= 2.9.1. | |
| Modificada | Alta (7.5) | 0.50% | — | Joomsky JS Help Desk | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through <= 2.9.2. | |
| Modificada | Crítica (9.1) | 0.63% | — | Joomsky JS Help Desk | 1/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Traversal.This issue affects JS Help Desk: from n/a through <= 2.9.2. | |
| Aplazada | Media (6.2) | 0.56% | — | BabelAIBabel HelpersAIBabel RuntimeAIBabel CoreAI | 11/3/2025 | 17/6/2026 | Babel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel will generate a polyfill for the `.replace` method that has quadratic complexity on some specific replacement pattern strings (i.e.… | |
| Aplazada | Media (6.1) | 0.14% | — | Appsero HelperAI | 11/3/2025 | 17/6/2026 | The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce validation on the 'appsero_helper' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts… | |
| Analizada | Alta (7.7) | 0.31% | — | Qnap Helpdesk | 7/3/2025 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: Helpdesk 3.3.3 and later | |
| Aplazada | Alta (8.8) | 0.50% | — | Templines Elementor Helper CoreAI | 27/2/2025 | 17/6/2026 | The Templines Elementor Helper Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.7. This is due to allowing arbitrary user meta updates. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to… | |
| Analizada | Media (4.8) | 0.27% | — | Helpdeskz | 26/2/2025 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket. | |
| Aplazada | Media (6.4) | 0.43% | — | Canadahelps Embedded Donation FormAI | 19/2/2025 | 17/6/2026 | The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedcdn' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (7.5) | 0.43% | — | Wiselyhub JS Help Desk | 13/2/2025 | 17/6/2026 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Analizada | Media (5.5) | 0.29% | — | Solarwinds WEB Help Desk | 11/2/2025 | 17/6/2026 | SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software. | |
| Aplazada | Media (6.1) | 0.18% | — | Paulswarthout Child-themes-helperAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in paulswarthout Child Themes Helper child-themes-helper allows Path Traversal.This issue affects Child Themes Helper: from n/a through <= 2.2.7. | |
| Aplazada | Media (4.3) | 0.42% | — | Jshelpdesk THE Ultimate Help Desk AND Support PluginAI | 4/2/2025 | 17/6/2026 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.26% | — | Codebard Help Desk | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Stored XSS.This issue affects CodeBard Help Desk: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.1) | 0.30% | — | E Marten EU Dsgvo HelperAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E. Marten EU DSGVO Helper dsgvo allows Reflected XSS.This issue affects EU DSGVO Helper: from n/a through <= 1.0.6.1. |