Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.2%—Tenmiles Helpdesk Pilot21/12/201317/6/2026
Cross-site scripting (XSS) vulnerability in Tenmiles Helpdesk Pilot allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI for a ticket.
ModificadaAlta (7.5)2.0%💥 ExploitCOM Huruhelpdesk28/7/201016/6/2026
SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail action to index.php.
ModificadaMedia (4.3)2.3%💥 ExploitViart Helpdesk4/1/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id…
ModificadaMedia (4.3)1.6%💥 ExploitCromosoft Facil Helpdesk4/1/201016/6/2026
Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
ModificadaMedia (6.8)1.9%💥 ExploitCromosoft Facil Helpdesk4/1/201016/6/2026
PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PHP code via a URL in the lng parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
ModificadaAlta (7.5)0.93%💥 ExploitZenhelpdesk ZEN Help Desk27/7/200916/6/2026
Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp.
ModificadaMedia (4.3)1.2%—Webhelpdesk WEB Help Desk7/4/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Web Help Desk 9.1.22 (evaluation version) allow remote attackers to inject arbitrary web script or HTML via the (1) Report Name, (2) Asset No., and (3) Full Name fields in a Models action. NOTE: the provenance of this information is unknown; the details are…
ModificadaMedia (5)6.5%💥 ExploitOneorzero Helpdesk12/3/200916/6/2026
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter.
ModificadaMedia (5)1.2%—Cerberus HelpdeskWebgroupmedia Cerberus Helpdesk6/3/200916/6/2026
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.
ModificadaAlta (7.5)0.97%💥 ExploitActivewebsoftwares Active WEB Helpdesk2/3/200916/6/2026
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
ModificadaMedia (4.3)1.0%—Webhelpdesk WEB Help Desk27/1/200916/6/2026
Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa.
ModificadaMedia (4.3)1.5%💥 ExploitAstrosoft Helpdesk6/2/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for…
ModificadaAlta (7.5)6.8%💥 ExploitPmos Helpdesk28/12/200716/6/2026
form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.
ModificadaMedia (6.8)7.1%💥 ExploitViart CMSViart HelpdeskViart Shop EvaluationViart Shop Free13/12/200716/6/2026
PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of these details are obtained from third…
ModificadaAlta (7.5)1.1%—Phphelpdesk10/11/200716/6/2026
SQL injection vulnerability in the login page in phphelpdesk 0.6.16 allows remote attackers to execute arbitrary SQL commands via unspecified parameters related to the "login procedures."
ModificadaMedia (6.8)1.8%💥 ExploitPhphelpdesk10/11/200716/6/2026
Directory traversal vulnerability in index.php in phphelpdesk 0.6.16 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the whattodo parameter.
ModificadaMedia (4.3)1.9%—Oneorzero Helpdesk30/10/200716/6/2026
Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description…
ModificadaMedia (4.3)1.9%—Grouplink Ehelpdesk3/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in GroupLink eHelpDesk 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) NA_DISPLAYNAME parameter in helpdesk/user/rf_create.jsp and the (2) username and (3) LDAPError parameters in index2.jsp. NOTE: the provenance of this information is…
ModificadaAlta (7.5)2.7%💥 ExploitUltimate Helpdesk7/12/200616/6/2026
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
ModificadaMedia (6.8)1.9%💥 ExploitUltimate Helpdesk7/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
ModificadaMedia (6.8)1.8%💥 ExploitCerberus Helpdesk7/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject arbitrary web script or HTML via the js parameter. NOTE: The provenance of this information is unknown; the details are obtained solely…
ModificadaMedia (6.8)2.9%💥 ExploitACE HelpdeskInverseflow Help DeskPmos Helpdesk28/11/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.
ModificadaAlta (7.5)1.8%—Oneorzero Helpdesk24/10/200616/6/2026
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
ModificadaMedia (5)2.8%💥 ExploitCerberus Helpdesk20/10/200616/6/2026
rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain sensitive information (ticket data) via a direct request.
ModificadaAlta (7.5)1.8%—Cerberus Helpdesk5/9/200616/6/2026
(1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, allows remote attackers to bypass security restrictions and obtain sensitive information via the ticket parameter. NOTE: the provenance of…
Orbitaley — Vulnerabilidades