Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.49% | — | Helpiewp Accordion & FAQ | 27/6/2023 | 17/6/2026 | The Accordion & FAQ WordPress plugin before 1.9.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.47% | — | Ladybirdweb Faveo Helpdesk | 24/6/2023 | 17/6/2026 | Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the application. This occurs because the application is vulnerable to stored XSS. | |
| Modificada | Alta (8.8) | 0.47% | — | Jshelpdesk | 23/6/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in JS Help Desk js-support-ticket allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk: from n/a through 2.7.7. | |
| Modificada | Media (5.4) | 0.46% | — | Help Desk WP Project Help Desk WP | 15/5/2023 | 17/6/2026 | The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks. | |
| Modificada | Media (6.5) | 0.56% | — | Wpruby Ruby Help Desk | 2/5/2023 | 17/6/2026 | The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own. | |
| Modificada | Media (5.4) | 0.38% | — | Webhelpagency WHA Puzzle | 18/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions. | |
| Modificada | Media (6.1) | 0.69% | — | Helpy.io Helpy | 4/4/2023 | 17/6/2026 | Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. This is possible because the application does not correctly validate the attachments sent by customers in the ticket. | |
| Modificada | Alta (8.8) | 0.80% | — | Ladybirdweb Faveo Helpdesk | 24/3/2023 | 17/6/2026 | Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection. | |
| Analizada | Crítica (9.8) | 2.7% | ⚠ Explotación activa | Helpsystems Cobalt Strike | 24/3/2023 | 17/6/2026 | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI. | |
| Modificada | Crítica (9.8) | 2.2% | — | Wyomind Help Desk | 8/3/2023 | 17/6/2026 | Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting. | |
| Modificada | Crítica (9.8) | 1.4% | — | Wyomind Help Desk | 8/3/2023 | 17/6/2026 | An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field. | |
| Modificada | Crítica (9) | 1.0% | — | Wyomind Help Desk | 8/3/2023 | 17/6/2026 | Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field. | |
| Modificada | Alta (8.8) | 0.26% | — | Wiselyhub JS Help Desk | 2/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions. | |
| Modificada | Media (6.1) | 43% | 💥 Exploit | Matbao WP Helper Premium | 26/1/2023 | 17/6/2026 | The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability. | |
| Modificada | Media (6.1) | 0.60% | — | Texthelpers Project Texthelpers | 22/12/2022 | 17/6/2026 | A vulnerability was found in ahorner text-helpers up to 1.0.x. It has been declared as critical. This vulnerability affects unknown code of the file lib/text_helpers/translation.rb. The manipulation of the argument link leads to use of web link to untrusted target with window.opener access. The attack can be initiated… | |
| Modificada | Media (6.1) | 0.37% | — | Siemens PLM Help Server | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in PLM Help Server V4.2 (All versions). A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected application that could allow an attacker to execute malicious javascript code by tricking users into accessing a malicious link. | |
| Modificada | Media (5.3) | 0.84% | — | Helpful Project Helpful | 17/10/2022 | 17/6/2026 | The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings | |
| Modificada | Baja (3.3) | 0.19% | — | Samsung Uphelper Library | 7/10/2022 | 17/6/2026 | Implicit intent hijacking vulnerability in UPHelper library prior to version 3.0.12 allows attackers to access sensitive information via implicit intent. | |
| Modificada | Media (5.4) | 0.53% | — | Webhelpagency WHA Crossword | 23/9/2022 | 17/6/2026 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA Crossword plugin <= 1.1.10 at WordPress. | |
| Analizada | Media (6.1) | 46% | ⚠ Explotación activa💥 PoC | Helpsystems Cobalt Strike | 22/9/2022 | 17/6/2026 | An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new… | |
| Modificada | Media (5.4) | 0.50% | — | Webhelpagency WHA Wordsearch | 21/9/2022 | 17/6/2026 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Word Search Puzzles game plugin <= 2.0.1 at WordPress. | |
| Modificada | Media (5.4) | 0.68% | — | Webhelpagency WHA Crossword | 21/9/2022 | 17/6/2026 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Crossword plugin <= 1.1.10 at WordPress. | |
| Modificada | Media (6.1) | 0.44% | — | Sysaid Help Desk | 11/9/2022 | 17/6/2026 | SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262. | |
| Modificada | Media (6.1) | 0.44% | — | Sysaid Help Desk | 11/9/2022 | 17/6/2026 | SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258. | |
| Modificada | Media (6.1) | 0.44% | — | Sysaid Help Desk | 11/9/2022 | 17/6/2026 | SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241. |