Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.13%—Wpmanageninja Fluent SupportAI22/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Cross Site Request Forgery.This issue affects Fluent Support: from n/a through <= 1.9.1.
AplazadaAlta (8.1)0.26%—Zohocorp Asset ExplorerAIZohocorp Servicedesk PlusAIZohocorp Servicedesk Plus MSPAIZohocorp Supportcenter PlusAI20/8/202517/6/2026
There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions…
AplazadaAlta (8.1)0.66%—Schiocco Support BoardAI20/8/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board supportboard allows PHP Local File Inclusion.This issue affects Support Board: from n/a through <= 3.8.0.
AplazadaAlta (7.1)0.24%—Schiocco Support BoardAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Support Board: from n/a through <= 3.8.0.
AplazadaAlta (7.1)0.24%—Themepassion Support TicketAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Support Ticket support-ticket allows Reflected XSS.This issue affects Support Ticket: from n/a through <= 1.9.
AplazadaCrítica (9.8)0.45%—Themepassion Support TicketAI20/8/202517/6/2026
Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.This issue affects Support Ticket: from n/a through <= 1.9.
AplazadaAlta (8.4)0.17%—HP Hotkey SupportAI15/8/202517/6/2026
A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support software, which might allow escalation of privilege. HP is releasing software updates to mitigate the potential vulnerability.
AnalizadaAlta (7.8)0.11%—Dell Supportassist FOR Home PCS14/8/202517/6/2026
SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment vulnerability in the Installer. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
AnalizadaAlta (7.8)0.11%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS14/8/202517/6/2026
SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.
AnalizadaAlta (7.8)0.10%—Dell Supportassist FOR Business PCS14/8/202517/6/2026
SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
AplazadaMedia (5.4)0.13%—Intel Driver AND Support Assistant ToolAI12/8/202517/6/2026
Uncontrolled search path element for some Intel(R) Driver &amp; Support Assistant Tool software before version 24.6.49.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.15%—Dell Supportassist OS Recovery6/8/202517/6/2026
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaBaja (2.4)0.18%—Dell Supportassist OS Recovery6/8/202517/6/2026
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
AnalizadaAlta (8.6)0.16%—Broadcom Brocade Active Support Connectivity Gateway17/7/202517/6/2026
Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and 8036.
AnalizadaAlta (7.1)0.24%—Broadcom Brocade Active Support Connectivity Gateway17/7/202517/6/2026
Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.
AnalizadaCrítica (9.8)0.36%—Schiocco Support Board9/7/202517/6/2026
The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute…
AnalizadaCrítica (9.8)0.90%—Schiocco Support Board9/7/202517/6/2026
The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions up to, and including, 3.8.0. This makes it possible for attackers to delete arbitrary files on the server, which can easily lead to remote code…
AnalizadaMedia (5.8)0.12%—HP Support Assistant8/7/202517/6/2026
A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbitrary file deletion.
AplazadaMedia (5.3)0.31%—Guest SupportAI8/7/202517/6/2026
The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteMassTickets' function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete…
AnalizadaCrítica (9.8)0.76%—HPE Insight Remote Support1/7/202517/6/2026
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
AnalizadaAlta (7.5)46%—HPE Insight Remote Support1/7/202517/6/2026
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
AnalizadaAlta (7.5)0.54%—HPE Insight Remote Support1/7/202517/6/2026
A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service
AnalizadaAlta (8.6)0.95%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support16/6/202517/6/2026
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
AnalizadaMedia (4.8)0.39%—Oretnom23 Customer Support System16/6/202517/6/2026
Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote attackers to execute arbitrary code via the page parameter.
AnalizadaAlta (8.7)0.50%—Oretnom23 Customer Support System16/6/202517/6/2026
SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the /customer_support/manage_user.php endpoint.