Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.13% | — | Wpmanageninja Fluent SupportAI | 22/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Cross Site Request Forgery.This issue affects Fluent Support: from n/a through <= 1.9.1. | |
| Aplazada | Alta (8.1) | 0.26% | — | Zohocorp Asset ExplorerAIZohocorp Servicedesk PlusAIZohocorp Servicedesk Plus MSPAIZohocorp Supportcenter PlusAI | 20/8/2025 | 17/6/2026 | There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions… | |
| Aplazada | Alta (8.1) | 0.66% | — | Schiocco Support BoardAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board supportboard allows PHP Local File Inclusion.This issue affects Support Board: from n/a through <= 3.8.0. | |
| Aplazada | Alta (7.1) | 0.24% | — | Schiocco Support BoardAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Support Board: from n/a through <= 3.8.0. | |
| Aplazada | Alta (7.1) | 0.24% | — | Themepassion Support TicketAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Support Ticket support-ticket allows Reflected XSS.This issue affects Support Ticket: from n/a through <= 1.9. | |
| Aplazada | Crítica (9.8) | 0.45% | — | Themepassion Support TicketAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.This issue affects Support Ticket: from n/a through <= 1.9. | |
| Aplazada | Alta (8.4) | 0.17% | — | HP Hotkey SupportAI | 15/8/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support software, which might allow escalation of privilege. HP is releasing software updates to mitigate the potential vulnerability. | |
| Analizada | Alta (7.8) | 0.11% | — | Dell Supportassist FOR Home PCS | 14/8/2025 | 17/6/2026 | SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment vulnerability in the Installer. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Analizada | Alta (7.8) | 0.11% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 14/8/2025 | 17/6/2026 | SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | |
| Analizada | Alta (7.8) | 0.10% | — | Dell Supportassist FOR Business PCS | 14/8/2025 | 17/6/2026 | SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Driver AND Support Assistant ToolAI | 12/8/2025 | 17/6/2026 | Uncontrolled search path element for some Intel(R) Driver & Support Assistant Tool software before version 24.6.49.8 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Supportassist OS Recovery | 6/8/2025 | 17/6/2026 | Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Baja (2.4) | 0.18% | — | Dell Supportassist OS Recovery | 6/8/2025 | 17/6/2026 | Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Analizada | Alta (8.6) | 0.16% | — | Broadcom Brocade Active Support Connectivity Gateway | 17/7/2025 | 17/6/2026 | Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and 8036. | |
| Analizada | Alta (7.1) | 0.24% | — | Broadcom Brocade Active Support Connectivity Gateway | 17/7/2025 | 17/6/2026 | Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure. | |
| Analizada | Crítica (9.8) | 0.36% | — | Schiocco Support Board | 9/7/2025 | 17/6/2026 | The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute… | |
| Analizada | Crítica (9.8) | 0.90% | — | Schiocco Support Board | 9/7/2025 | 17/6/2026 | The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions up to, and including, 3.8.0. This makes it possible for attackers to delete arbitrary files on the server, which can easily lead to remote code… | |
| Analizada | Media (5.8) | 0.12% | — | HP Support Assistant | 8/7/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbitrary file deletion. | |
| Aplazada | Media (5.3) | 0.31% | — | Guest SupportAI | 8/7/2025 | 17/6/2026 | The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteMassTickets' function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete… | |
| Analizada | Crítica (9.8) | 0.76% | — | HPE Insight Remote Support | 1/7/2025 | 17/6/2026 | A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. | |
| Analizada | Alta (7.5) | 46% | — | HPE Insight Remote Support | 1/7/2025 | 17/6/2026 | A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. | |
| Analizada | Alta (7.5) | 0.54% | — | HPE Insight Remote Support | 1/7/2025 | 17/6/2026 | A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service | |
| Analizada | Alta (8.6) | 0.95% | — | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 16/6/2025 | 17/6/2026 | The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution. | |
| Analizada | Media (4.8) | 0.39% | — | Oretnom23 Customer Support System | 16/6/2025 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote attackers to execute arbitrary code via the page parameter. | |
| Analizada | Alta (8.7) | 0.50% | — | Oretnom23 Customer Support System | 16/6/2025 | 17/6/2026 | SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the /customer_support/manage_user.php endpoint. |