Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.11%—Intel Oneapi Dpc++ C++ CompilerAIIntel Fpga Support PackageAI11/11/202517/6/2026
Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 2025.0.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation…
AplazadaMedia (5.4)0.13%—Intel Driver AND Support AssistantAI11/11/202517/6/2026
Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This result may potentially…
AplazadaMedia (5.4)0.14%—Intel System Support UtilityAI11/11/202517/6/2026
Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially occur…
AplazadaCrítica (10)0.45%—Villatheme Happy Helpdesk Support Ticket SystemAI6/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code Inclusion.This issue affects HAPPY: from n/a through <= 1.0.7.
AplazadaCrítica (10)0.43%—Plugify Support Ticket System FOR WoocommerceAI6/11/20255/10/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Plugify Support Ticket System for WooCommerce (Premium) support-ticket-system-for-woocommerce allows Using Malicious Files.This issue affects Support Ticket System for WooCommerce (Premium): from n/a through <= 2.0.7.
AplazadaAlta (7.5)0.40%—Majesticsupport Majestic SupportAI29/10/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File Inclusion.This issue affects Majestic Support: from n/a through <= 1.0.7.
AnalizadaMedia (5.5)0.11%—Dell Supportassist OS Recovery27/10/202517/6/2026
Dell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
AplazadaAlta (8.5)0.17%—Remotecall Remote Support ProgramAI15/10/202517/6/2026
RemoteCall Remote Support Program (for Operator) versions prior to 5.3.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.
AplazadaAlta (8.5)0.17%—Remotecall Remote Support ProgramAI15/10/202517/6/2026
RemoteCall Remote Support Program (for Operator) versions prior to 5.1.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.
AnalizadaAlta (7.1)0.13%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS13/10/202517/6/2026
SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. A low privileged attacker with local access to the system could potentially exploit this vulnerability to delete arbitrary files only in that…
AnalizadaAlta (7.1)0.22%—Opensupports3/10/202517/6/2026
OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor is the owner of that list. A Level 1 staff member can modify the supervision relationship of a third party (the target user), who can then view the tickets of the added…
AnalizadaMedia (6.9)0.30%—Opensupports3/10/202517/6/2026
Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'any', enabling unauthenticated SSRF for internal network scanning and service interaction. This issue affects OpenSupports: 4.11.0.
AplazadaAlta (7.1)0.36%—OpensupportsAI3/10/202517/6/2026
The endpoint POST /api/staff/get-new-tickets concatenates the user-controlled parameter departmentId directly into the SQL WHERE clause without parameter binding. As a result, an authenticated staff user (level ≥ 1) can inject SQL to alter the filter logic, effectively bypassing department scoping and disclosing…
AnalizadaMedia (5.8)0.12%—HP Support Assistant1/10/202517/6/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.
AplazadaAlta (7.1)0.13%—Casengo Live Chat SupportAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support the-casengo-chat-widget allows Stored XSS.This issue affects Casengo Live Chat Support: from n/a through <= 2.1.4.
AplazadaAlta (7.2)0.47%—Awesomesupport Awesome SupportAI22/9/202530/9/2026
Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome Support: from n/a through <= 6.3.5.
AplazadaMedia (4.3)0.25%—Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI22/9/20251/10/2026
Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.1.
AplazadaMedia (6.5)0.34%💥 PoCSupportcandyAI20/9/202517/6/2026
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. This is due to missing rate limiting on the OTP verification for guest login. This makes it possible for unauthenticated attackers to bypass…
AplazadaMedia (5.3)0.29%—Awesomesupport Awesome SupportAI9/9/202517/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6.
AplazadaMedia (5.3)0.29%—Majesticsupport Majestic SupportAI9/9/202517/6/2026
Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.1.0.
AplazadaMedia (6.5)0.23%—Villatheme Happy Helpdesk Support Ticket SystemAI5/9/202517/6/2026
Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.6.
AplazadaMedia (5.3)0.22%—Devitems Support GenixAI3/9/202517/6/2026
Missing Authorization vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Support Genix: from n/a through <= 1.4.23.
AplazadaAlta (8.8)0.50%—Netsupport ManagerAI30/8/202517/6/2026
A stack-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially leak a limited amount of memory.
AplazadaCrítica (9.3)0.66%—Netsupport ManagerAI30/8/202517/6/2026
A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code.
AnalizadaMedia (6.9)0.11%—Heinlein-support Check MK Python API28/8/202525/9/2026
Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.