Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Solaplugins Sola Support TicketAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in SolaPlugins Sola Support Ticket allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sola Support Ticket: from n/a through 3.17. | |
| Aplazada | Media (5.4) | 0.17% | — | Hive SupportAI | 6/6/2025 | 17/6/2026 | The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the hs_update_ai_chat_settings() function. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.32% | — | Hive SupportAI | 6/6/2025 | 17/6/2026 | The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (7.1) | 0.13% | — | HP Support Assistant | 5/6/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write. | |
| Aplazada | Crítica (9.3) | 0.35% | — | Majesticsupport Majestic SupportAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support Majestic Support majestic-support allows SQL Injection.This issue affects Majestic Support: from n/a through <= 1.1.0. | |
| Analizada | Media (6.5) | 1.6% | — | Zohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. | |
| Aplazada | Media (5.3) | 0.26% | — | Majesticsupport Majestic SupportAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.0. | |
| Aplazada | Media (4.3) | 0.25% | — | Ninjateam Gdpr Ccpa Compliance SupportAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR CCPA Compliance Support: from n/a through <= 2.7.3. | |
| Aplazada | Alta (8.5) | 0.32% | — | Lambertgroup Multimedia Responsive Carousel With Image Video Audio SupportAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multimedia Responsive Carousel with Image Video Audio Support multimedia-carousel allows SQL Injection.This issue affects Multimedia Responsive Carousel with Image Video Audio Support: from n/a through <=… | |
| Analizada | Media (5.4) | 0.29% | — | Ablyperu SVG Uploads Support | 15/5/2025 | 17/6/2026 | The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Aplazada | Media (5.4) | 0.15% | — | Qusupport LiveagentAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent liveagent allows Cross Site Request Forgery.This issue affects LiveAgent: from n/a through <= 4.4.7. | |
| Aplazada | Alta (7.1) | 0.23% | — | Crmperks CRM Perks Support-xAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks support-x allows Reflected XSS.This issue affects CRM Perks: from n/a through <= 1.1.7. | |
| Aplazada | Media (5.9) | 0.27% | — | Maros Pristas Gravity Forms CSS Themes With Fontawesome AND Placeholder SupportAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maros Pristas Gravity Forms CSS Themes with Fontawesome and Placeholders gravity-forms-css-themes-with-fontawesome-and-placeholder-support allows Stored XSS.This issue affects Gravity Forms CSS Themes with Fontawesome… | |
| Aplazada | Alta (7.1) | 0.29% | — | Hive SupportAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hive Support Hive Support hive-support allows Reflected XSS.This issue affects Hive Support: from n/a through <= 1.2.5. | |
| Aplazada | Alta (7.5) | 0.47% | — | Hive SupportAI | 17/4/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Hive Support Hive Support hive-support allows Retrieve Embedded Sensitive Data.This issue affects Hive Support: from n/a through <= 1.2.6. | |
| Aplazada | Media (6.5) | 0.29% | — | Hive SupportAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Hive Support Hive Support hive-support allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hive Support: from n/a through <= 1.2.5. | |
| Aplazada | Media (6.5) | 0.22% | — | Hive SupportAI | 10/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hive Support Hive Support hive-support allows Stored XSS.This issue affects Hive Support: from n/a through <= 1.2.11. | |
| Aplazada | Media (6.5) | 0.33% | — | Hive SupportAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Hive Support Hive Support hive-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hive Support: from n/a through <= 1.2.5. | |
| Aplazada | Alta (7.5) | 0.47% | — | KB SupportAI | 5/4/2025 | 17/6/2026 | The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the 'kbs' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in… | |
| Aplazada | Media (5.9) | 0.41% | — | Socialintents Live-chat-support-by-social-intentsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in socialintents Social Intents live-chat-support-by-social-intents allows Stored XSS.This issue affects Social Intents: from n/a through <= 1.6.19. | |
| Aplazada | Alta (7.1) | 0.29% | — | M. ALI Saleem Support Helpdesk Ticket System LiteAI | 3/4/2025 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alisaleem252 Support Helpdesk Ticket System Lite ticket-help-desk-system-lite allows Reflected XSS.This issue affects Support Helpdesk Ticket System Lite: from n/a through 4.5.2. | |
| Aplazada | Alta (7.1) | 0.39% | — | Mayeenul Islam NanosupportAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mayeenul Islam NanoSupport nanosupport allows Reflected XSS.This issue affects NanoSupport: from n/a through <= 0.6.0. | |
| Aplazada | Alta (7.5) | 0.65% | — | Awesomesupport Awesome SupportAI | 1/4/2025 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Aplazada | Media (4.3) | 0.23% | — | Mayeenul Islam NanosupportAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Mayeenul Islam NanoSupport nanosupport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NanoSupport: from n/a through <= 0.6.0. | |
| Aplazada | Media (6.5) | 0.20% | — | Ninjateam Click TO Chat WP Support ALL IN ONE Floating WidgetAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.4. |