Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.11% | — | Intel Oneapi Dpc++ C++ CompilerAIIntel Fpga Support PackageAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 2025.0.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation… | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Driver AND Support AssistantAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This result may potentially… | |
| Aplazada | Media (5.4) | 0.14% | — | Intel System Support UtilityAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially occur… | |
| Aplazada | Crítica (10) | 0.45% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 6/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code Inclusion.This issue affects HAPPY: from n/a through <= 1.0.7. | |
| Aplazada | Crítica (10) | 0.43% | — | Plugify Support Ticket System FOR WoocommerceAI | 6/11/2025 | 5/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Plugify Support Ticket System for WooCommerce (Premium) support-ticket-system-for-woocommerce allows Using Malicious Files.This issue affects Support Ticket System for WooCommerce (Premium): from n/a through <= 2.0.7. | |
| Aplazada | Alta (7.5) | 0.40% | — | Majesticsupport Majestic SupportAI | 29/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File Inclusion.This issue affects Majestic Support: from n/a through <= 1.0.7. | |
| Analizada | Media (5.5) | 0.11% | — | Dell Supportassist OS Recovery | 27/10/2025 | 17/6/2026 | Dell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Aplazada | Alta (8.5) | 0.17% | — | Remotecall Remote Support ProgramAI | 15/10/2025 | 17/6/2026 | RemoteCall Remote Support Program (for Operator) versions prior to 5.3.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution. | |
| Aplazada | Alta (8.5) | 0.17% | — | Remotecall Remote Support ProgramAI | 15/10/2025 | 17/6/2026 | RemoteCall Remote Support Program (for Operator) versions prior to 5.1.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution. | |
| Analizada | Alta (7.1) | 0.13% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 13/10/2025 | 17/6/2026 | SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. A low privileged attacker with local access to the system could potentially exploit this vulnerability to delete arbitrary files only in that… | |
| Analizada | Alta (7.1) | 0.22% | — | Opensupports | 3/10/2025 | 17/6/2026 | OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor is the owner of that list. A Level 1 staff member can modify the supervision relationship of a third party (the target user), who can then view the tickets of the added… | |
| Analizada | Media (6.9) | 0.30% | — | Opensupports | 3/10/2025 | 17/6/2026 | Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'any', enabling unauthenticated SSRF for internal network scanning and service interaction. This issue affects OpenSupports: 4.11.0. | |
| Aplazada | Alta (7.1) | 0.36% | — | OpensupportsAI | 3/10/2025 | 17/6/2026 | The endpoint POST /api/staff/get-new-tickets concatenates the user-controlled parameter departmentId directly into the SQL WHERE clause without parameter binding. As a result, an authenticated staff user (level ≥ 1) can inject SQL to alter the filter logic, effectively bypassing department scoping and disclosing… | |
| Analizada | Media (5.8) | 0.12% | — | HP Support Assistant | 1/10/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write. | |
| Aplazada | Alta (7.1) | 0.13% | — | Casengo Live Chat SupportAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support the-casengo-chat-widget allows Stored XSS.This issue affects Casengo Live Chat Support: from n/a through <= 2.1.4. | |
| Aplazada | Alta (7.2) | 0.47% | — | Awesomesupport Awesome SupportAI | 22/9/2025 | 30/9/2026 | Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome Support: from n/a through <= 6.3.5. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI | 22/9/2025 | 1/10/2026 | Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.1. | |
| Aplazada | Media (6.5) | 0.34% | 💥 PoC | SupportcandyAI | 20/9/2025 | 17/6/2026 | The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. This is due to missing rate limiting on the OTP verification for guest login. This makes it possible for unauthenticated attackers to bypass… | |
| Aplazada | Media (5.3) | 0.29% | — | Awesomesupport Awesome SupportAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6. | |
| Aplazada | Media (5.3) | 0.29% | — | Majesticsupport Majestic SupportAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.1.0. | |
| Aplazada | Media (6.5) | 0.23% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.6. | |
| Aplazada | Media (5.3) | 0.22% | — | Devitems Support GenixAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Support Genix: from n/a through <= 1.4.23. | |
| Aplazada | Alta (8.8) | 0.50% | — | Netsupport ManagerAI | 30/8/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially leak a limited amount of memory. | |
| Aplazada | Crítica (9.3) | 0.66% | — | Netsupport ManagerAI | 30/8/2025 | 17/6/2026 | A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code. | |
| Analizada | Media (6.9) | 0.11% | — | Heinlein-support Check MK Python API | 28/8/2025 | 25/9/2026 | Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic. |