Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.38% | — | DAN Griffiths Beacon FOR HelpscoutAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Griffiths Beacon For Help Scout beacon-for-helpscout allows DOM-Based XSS.This issue affects Beacon For Help Scout: from n/a through <= 1.3.0. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Clarisse K Writer HelperAI | 16/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Clarisse K. Writer Helper writer-helper allows Upload a Web Shell to a Web Server.This issue affects Writer Helper: from n/a through <= 3.1.6. | |
| Modificada | Media (4.8) | 0.26% | — | Joomsky JS Help Desk | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomSky JS Help Desk js-support-ticket allows Stored XSS.This issue affects JS Help Desk: from n/a through <= 2.8.7. | |
| Aplazada | Alta (7.1) | 0.27% | — | Zackgilbert WphelpfulAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zackgilbert WPHelpful wphelpful allows Stored XSS.This issue affects WPHelpful: from n/a through <= 1.2.4. | |
| Aplazada | Alta (7.1) | 0.27% | — | Tevya Happiness-reports-for-help-scoutAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tevya Satisfaction Reports from Help Scout happiness-reports-for-help-scout allows Reflected XSS.This issue affects Satisfaction Reports from Help Scout: from n/a through <= 2.0.3. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wojciechborowicz Conversion-helperAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wojciechborowicz Conversion Helper conversion-helper allows Reflected XSS.This issue affects Conversion Helper: from n/a through <= 1.12. | |
| Analizada | Media (5.4) | 0.45% | — | Ladybirdweb Faveo Helpdesk | 1/11/2024 | 17/6/2026 | An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields | |
| Analizada | Crítica (9.8) | 0.44% | — | Joomsky JS Help Desk | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.6. | |
| Aplazada | Media (5.3) | 0.38% | — | Alex Volkov WP Accessibility HelperAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.9. | |
| Aplazada | Alta (8.2) | 0.38% | — | Ladybird WEB Solution Faveo-helpdeskAI | 22/10/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file. | |
| Modificada | Media (5.3) | 0.39% | — | Matbao WP Helper Premium | 10/10/2024 | 17/6/2026 | The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send_mail_test' function in all versions up to, and including, 4.6.1. This makes it possible for unauthenticated attackers to send emails containing any content and… | |
| Aplazada | Media (5.9) | 0.27% | — | Essekia Helpie FAQAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Essekia Helpie FAQ helpie-faq allows Stored XSS.This issue affects Helpie FAQ: from n/a through <= 1.27. | |
| Aplazada | Alta (7.6) | 0.47% | — | Helpdeskz Helpdesk ZAI | 23/9/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box. | |
| Analizada | Media (6.1) | 0.41% | — | Wpfactory Helper | 13/9/2024 | 17/6/2026 | The WPFactory Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Analizada | Media (4.8) | 0.25% | — | Qnap Helpdesk | 6/9/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following version: Helpdesk 3.3.1 and later | |
| Analizada | Media (4.3) | 0.26% | — | Volkov WP Accessibility Helper | 29/8/2024 | 17/6/2026 | The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authenticated attackers,… | |
| Analizada | Crítica (9.1) | 93% | ⚠ Explotación activa | Solarwinds WEB Help Desk | 21/8/2024 | 17/6/2026 | The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data. | |
| Analizada | Crítica (9.8) | 85% | ⚠ Explotación activa | Solarwinds WEB Help Desk | 13/8/2024 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without… | |
| Aplazada | Crítica (9.8) | 38% | — | Jshelpdesk JS Help DeskAI | 13/8/2024 | 17/6/2026 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the… | |
| Aplazada | Media (5.9) | 0.27% | — | Codexhelp Master PopupsAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodexHelp Master Popups allows Stored XSS.This issue affects Master Popups: from n/a through 1.0.3. | |
| Modificada | Media (6.1) | 0.33% | — | Dj-extensions Dj-helpfularticles | 9/7/2024 | 17/6/2026 | XSS vulnerability in DJ-HelpfulArticles component for Joomla. | |
| Aplazada | Alta (8.8) | 0.40% | — | PrestashopAIFmemodules HelpdeskAI | 24/6/2024 | 17/6/2026 | SQL Injection vulnerability in the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via 'Tickets::getsearchedtickets()' | |
| Aplazada | Crítica (10) | 0.51% | — | PrestashopAIFmemodules HelpdeskAI | 19/6/2024 | 17/6/2026 | In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods `HelpdeskHelpdeskModuleFrontController::submitTicket()` and `HelpdeskHelpdeskModuleFrontController::replyTicket()` allow upload of .php files on a… | |
| Modificada | Alta (7.3) | 0.30% | — | Awesomesupport Awesome Support Wordpress Helpdesk & Support | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5. | |
| Modificada | Alta (8.8) | 0.32% | — | Volkov WP Accessibility Helper | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH).This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.5. |