Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Mamboxchange A6mambohelpdesk | 31/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | |
| Modificada | Media (4.3) | 2.0% | — | Vanillasoft Helpdesk | 13/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.asp in VanillaSoft Helpdesk 2005 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Cerberus Helpdesk | 1/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields. | |
| Modificada | Alta (7.5) | 1.1% | — | Help Desk Point Software Helpdeskpoint | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Cerberus Helpdesk | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Cerberus Helpdesk | 20/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Helpdesk Issue Manager | 30/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | EZY Helpdesk Ezyhelpdesk | 26/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter. | |
| Modificada | Media (5) | 1.5% | — | Cerberus Helpdesk | 5/11/2005 | 16/6/2026 | attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Helpdesk Software Hesk | 21/9/2005 | 16/6/2026 | Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie. | |
| Modificada | Alta (7.5) | 1.6% | — | Helpdesk Software Hesk | 8/9/2005 | 16/6/2026 | Helpdesk software Hesk 0.92 does not properly verify usernames and passwords, which allows remote attackers to bypass authentication via a direct request to admin_main.php. | |
| Modificada | Media (4.3) | 1.3% | — | Cerberus Helpdesk | 16/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php. | |
| Modificada | Media (5) | 1.5% | — | Cerberus Helpdesk | 16/6/2005 | 16/6/2026 | Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Netsupport DNA Helpdesk | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter. | |
| Modificada | Media (5) | 5.4% | 💥 Exploit | Polar Software Helpdesk | 31/12/2004 | 16/6/2026 | Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Leigh Business Enterprises WEB Helpdesk | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Oneorzero Helpdesk | 9/6/2003 | 16/6/2026 | SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter. | |
| Modificada | Alta (10) | 8.1% | 💥 Exploit | Oneorzero Helpdesk | 9/6/2003 | 16/6/2026 | one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script. | |
| Modificada | Media (6.4) | 1.2% | 💥 Exploit | Luis Bernardo Myhelpdesk | 4/10/2002 | 16/6/2026 | SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Luis Bernardo Myhelpdesk | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via a (1) Title or (2) Description when a new ticket is created by a support assistant, via the "id" parameter to the index.php script with the (3) tickettime, (4)… |