Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.47% | — | Wiselyhub JS Help Desk | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.3. | |
| Analizada | Crítica (9.1) | 0.84% | — | Joomsky JS Help Desk | 17/5/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Using Malicious Files.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.7. | |
| Aplazada | Media (5.1) | 0.15% | — | Motorola Device HelpAI | 3/5/2024 | 17/6/2026 | A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission. | |
| Aplazada | Media (5) | 0.15% | — | Motorola Device HelpAI | 3/5/2024 | 17/6/2026 | An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs. | |
| Aplazada | Alta (7.1) | 0.39% | — | Matbao WP Helper PremiumAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mat Bao Corp WP Helper Premium allows Reflected XSS.This issue affects WP Helper Premium: from n/a before 4.6.0. | |
| Modificada | Alta (8.6) | 0.44% | — | Joomsky JS Help Desk | 17/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1. | |
| Analizada | Media (6.1) | 0.29% | — | Helpdeskz | 1/3/2024 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability has been found in HelpDeskZ affecting version 2.0.2 and earlier. This vulnerability could allow an attacker to send a specially crafted JavaScript payload within the email field and partially take control of an authenticated user's browser session. | |
| Analizada | Crítica (9.8) | 1.5% | — | Livehelperchat Live Helper Chat | 29/2/2024 | 17/6/2026 | Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php. | |
| Modificada | Media (5.5) | 0.15% | — | Samsung Uphelper Library | 6/2/2024 | 17/6/2026 | Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implicit intent. | |
| Modificada | Crítica (9.8) | 0.83% | — | Wiselyhub JS Help Desk | 5/1/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 Exploit | Wiselyhub JS Help Desk | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1. | |
| Modificada | Alta (7.5) | 1.3% | — | Adobe Robohelp Server | 17/11/2023 | 17/6/2026 | Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction. | |
| Modificada | Alta (7.5) | 1.5% | — | Adobe Robohelp Server | 17/11/2023 | 17/6/2026 | Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction. | |
| Modificada | Alta (7.2) | 1.9% | — | Adobe Robohelp Server | 17/11/2023 | 17/6/2026 | Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to Remote Code Execution by an admin authenticated attacker. Exploitation of this issue does not require user interaction. | |
| Modificada | Alta (7.5) | 1.4% | — | Adobe Robohelp Server | 17/11/2023 | 17/6/2026 | Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction. | |
| Modificada | Media (6.5) | 1.2% | — | Adobe Robohelp Server | 17/11/2023 | 17/6/2026 | Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an low-privileged authenticated attacker. Exploitation of this issue does not require user interaction. | |
| Modificada | Alta (8.8) | 0.25% | — | Matbao WP Helper Premium | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mat Bao Corp WP Helper Premium plugin <= 4.5.1 versions. | |
| Modificada | Alta (8.8) | 2.0% | 💥 PoC | Spiceworks Help Desk Server | 9/11/2023 | 17/6/2026 | An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak… | |
| Modificada | Alta (8.8) | 0.52% | — | Debian LinuxBabeljs BabelBabeljs Babel-helper-define-polyfill-providerBabeljs Babel-plugin-polyfill-corejs2+5 | 12/10/2023 | 17/6/2026 | Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the… | |
| Modificada | Alta (7.5) | 0.80% | — | Helpdezk | 4/10/2023 | 17/6/2026 | SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the rows parameter of the jsonGrid route and extract all the information stored in the application. | |
| Modificada | Alta (8.6) | 0.73% | — | Helpdezk | 4/10/2023 | 17/6/2026 | Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to access the platform without authentication and retrieve personal data via the jsonGrid parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | Fresenius-kabi Pharmahelp Firmware | 22/8/2023 | 17/6/2026 | An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login information. | |
| Modificada | Media (6.1) | 0.41% | — | Wpfactory Helper | 5/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory WPFactory Helper plugin <= 1.5.2 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Codexin Media Library Helper | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Media Library Helper plugin <= 1.2.0 versions. | |
| Modificada | Alta (7.8) | 0.64% | — | Perimeter81 XPC Helpertool | 30/6/2023 | 17/6/2026 | com.perimeter81.osx.HelperTool in Perimeter81 10.0.0.19 on macOS allows Local Privilege Escalation (to root) via shell metacharacters in usingCAPath. |