Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Tenmiles Helpdesk Pilot | 21/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Tenmiles Helpdesk Pilot allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI for a ticket. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | COM Huruhelpdesk | 28/7/2010 | 16/6/2026 | SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail action to index.php. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Viart Helpdesk | 4/1/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id… | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Cromosoft Facil Helpdesk | 4/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Cromosoft Facil Helpdesk | 4/1/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PHP code via a URL in the lng parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Zenhelpdesk ZEN Help Desk | 27/7/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp. | |
| Modificada | Media (4.3) | 1.2% | — | Webhelpdesk WEB Help Desk | 7/4/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Web Help Desk 9.1.22 (evaluation version) allow remote attackers to inject arbitrary web script or HTML via the (1) Report Name, (2) Asset No., and (3) Full Name fields in a Models action. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Media (5) | 6.5% | 💥 Exploit | Oneorzero Helpdesk | 12/3/2009 | 16/6/2026 | Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter. | |
| Modificada | Media (5) | 1.2% | — | Cerberus HelpdeskWebgroupmedia Cerberus Helpdesk | 6/3/2009 | 16/6/2026 | Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Activewebsoftwares Active WEB Helpdesk | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Webhelpdesk WEB Help Desk | 27/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Astrosoft Helpdesk | 6/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for… | |
| Modificada | Alta (7.5) | 6.8% | 💥 Exploit | Pmos Helpdesk | 28/12/2007 | 16/6/2026 | form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter. | |
| Modificada | Media (6.8) | 7.1% | 💥 Exploit | Viart CMSViart HelpdeskViart Shop EvaluationViart Shop Free | 13/12/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (7.5) | 1.1% | — | Phphelpdesk | 10/11/2007 | 16/6/2026 | SQL injection vulnerability in the login page in phphelpdesk 0.6.16 allows remote attackers to execute arbitrary SQL commands via unspecified parameters related to the "login procedures." | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Phphelpdesk | 10/11/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in phphelpdesk 0.6.16 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the whattodo parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Oneorzero Helpdesk | 30/10/2007 | 16/6/2026 | Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description… | |
| Modificada | Media (4.3) | 1.9% | — | Grouplink Ehelpdesk | 3/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GroupLink eHelpDesk 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) NA_DISPLAYNAME parameter in helpdesk/user/rf_create.jsp and the (2) username and (3) LDAPError parameters in index2.jsp. NOTE: the provenance of this information is… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Ultimate Helpdesk | 7/12/2006 | 16/6/2026 | Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Ultimate Helpdesk | 7/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Cerberus Helpdesk | 7/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject arbitrary web script or HTML via the js parameter. NOTE: The provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Media (6.8) | 2.9% | 💥 Exploit | ACE HelpdeskInverseflow Help DeskPmos Helpdesk | 28/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php. | |
| Modificada | Alta (7.5) | 1.8% | — | Oneorzero Helpdesk | 24/10/2006 | 16/6/2026 | The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Cerberus Helpdesk | 20/10/2006 | 16/6/2026 | rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain sensitive information (ticket data) via a direct request. | |
| Modificada | Alta (7.5) | 1.8% | — | Cerberus Helpdesk | 5/9/2006 | 16/6/2026 | (1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, allows remote attackers to bypass security restrictions and obtain sensitive information via the ticket parameter. NOTE: the provenance of… |