Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.9%💥 ExploitMamboxchange A6mambohelpdesk31/7/200616/6/2026
PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
ModificadaMedia (4.3)2.0%—Vanillasoft Helpdesk13/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in default.asp in VanillaSoft Helpdesk 2005 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.
ModificadaMedia (4.3)2.0%💥 ExploitCerberus Helpdesk1/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.
ModificadaAlta (7.5)1.1%—Help Desk Point Software Helpdeskpoint31/12/200516/6/2026
SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.
ModificadaMedia (4.3)1.3%—Cerberus Helpdesk20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter.
ModificadaAlta (7.5)3.2%💥 ExploitCerberus Helpdesk20/12/200516/6/2026
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to…
ModificadaAlta (7.5)1.3%💥 ExploitHelpdesk Issue Manager30/11/200516/6/2026
Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.
ModificadaAlta (7.5)1.2%💥 ExploitEZY Helpdesk Ezyhelpdesk26/11/200516/6/2026
Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter.
ModificadaMedia (5)1.5%—Cerberus Helpdesk5/11/200516/6/2026
attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.
ModificadaAlta (7.5)3.0%💥 ExploitHelpdesk Software Hesk21/9/200516/6/2026
Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie.
ModificadaAlta (7.5)1.6%—Helpdesk Software Hesk8/9/200516/6/2026
Helpdesk software Hesk 0.92 does not properly verify usernames and passwords, which allows remote attackers to bypass authentication via a direct request to admin_main.php.
ModificadaMedia (4.3)1.3%—Cerberus Helpdesk16/6/200516/6/2026
Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.
ModificadaMedia (5)1.5%—Cerberus Helpdesk16/6/200516/6/2026
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.
ModificadaAlta (7.5)1.0%💥 ExploitNetsupport DNA Helpdesk31/12/200416/6/2026
SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter.
ModificadaMedia (5)5.4%💥 ExploitPolar Software Helpdesk31/12/200416/6/2026
Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.
ModificadaAlta (7.5)1.4%💥 ExploitLeigh Business Enterprises WEB Helpdesk31/12/200416/6/2026
SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5)2.5%💥 ExploitOneorzero Helpdesk9/6/200316/6/2026
SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.
ModificadaAlta (10)8.1%💥 ExploitOneorzero Helpdesk9/6/200316/6/2026
one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.
ModificadaMedia (6.4)1.2%💥 ExploitLuis Bernardo Myhelpdesk4/10/200216/6/2026
SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog.
ModificadaAlta (7.5)3.1%💥 ExploitLuis Bernardo Myhelpdesk4/10/200216/6/2026
Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via a (1) Title or (2) Description when a new ticket is created by a support assistant, via the "id" parameter to the index.php script with the (3) tickettime, (4)…
Orbitaley — Vulnerabilidades