Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 65% | ⚠ Explotación activa | Simple-help Simplehelp | 15/1/2025 | 17/6/2026 | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. | |
| Analizada | Alta (7.5) | 97% | ⚠ Explotación activa | Simple-help Simplehelp | 15/1/2025 | 4/8/2026 | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed… | |
| Analizada | Crítica (9.9) | 67% | ⚠ Explotación activa | Simple-help Simplehelp | 15/1/2025 | 17/6/2026 | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. | |
| Modificada | Media (6.1) | 0.28% | — | Codebard Help Desk | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Reflected XSS.This issue affects CodeBard Help Desk: from n/a through <= 1.1.2. | |
| Analizada | Media (5.4) | 0.17% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function. | |
| Analizada | Media (6.1) | 0.23% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function. | |
| Analizada | Alta (7.5) | 0.97% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function. | |
| Analizada | Alta (8.1) | 0.33% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the "WSCView/Delete" function. | |
| Analizada | Media (6.1) | 0.28% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function. | |
| Analizada | Media (6.5) | 0.70% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the WSConnector service. | |
| Analizada | Alta (8.8) | 0.45% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function. | |
| Analizada | Alta (7.5) | 0.76% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function. | |
| Analizada | Alta (7.5) | 0.76% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function. | |
| Analizada | Alta (7.5) | 0.76% | — | Zucchetti Helpdeskadvanced | 13/1/2025 | 17/6/2026 | Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function. | |
| Aplazada | Media (4.3) | 0.39% | — | Boldgrid Help ScoutAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Help Scout help-scout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Help Scout: from n/a through <= 6.5.6. | |
| Aplazada | Media (4.3) | 0.19% | — | Metorik-helperAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metorik Metorik – Reports & Email Automation for WooCommerce metorik-helper allows Cross Site Request Forgery.This issue affects Metorik – Reports & Email Automation for WooCommerce: from n/a through <= 1.7.1. | |
| Modificada | Media (5.4) | 0.16% | — | Codebard Help Desk | 31/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Request Forgery.This issue affects CodeBard Help Desk: from n/a through <= 1.1.1. | |
| Aplazada | Media (6.4) | 0.35% | — | Crmperks Wordpress Helpdesk IntegrationAI | 16/12/2024 | 17/6/2026 | The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'crm-perks-tickets' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (4.3) | 0.50% | — | Alex Volkov WP Accessibility HelperAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.4. | |
| Modificada | Media (5.4) | 0.45% | — | Joomsky JS Help Desk | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1. | |
| Modificada | Crítica (9.1) | 0.73% | — | Joomsky JS Help Desk | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1. | |
| Analizada | Media (5.5) | 0.50% | — | Solarwinds WEB Help Desk | 10/12/2024 | 17/6/2026 | SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited. | |
| Aplazada | Media (5.5) | 0.26% | — | SG HelperAI | 4/12/2024 | 17/6/2026 | The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that… | |
| Aplazada | Alta (7.1) | 0.35% | — | Zaymund TM Islamic HelperAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zaymund TM Islamic Helper tm-islamic-helper allows Reflected XSS.This issue affects TM Islamic Helper: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.30% | — | Ezlab Assist24 Help DeskAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ezlab Assist24 Help Desk assist24it allows DOM-Based XSS.This issue affects Assist24 Help Desk: from n/a through <= 20150401.2. |