Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.24% | — | Vanquish Woocommerce Support Ticket System | 1/2/2025 | 17/6/2026 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on the 'ajax_delete_message', 'ajax_get_customers_partial_list', and 'ajax_get_admins_list' functions in all versions up to, and including, 17.8. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.51% | — | Splunk Supporting Add-on FOR Active DirectoryAISplunk Sa-ldapsearchAI | 30/1/2025 | 17/6/2026 | In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack. | |
| Modificada | Media (6.1) | 0.24% | — | Logon KB Support | 27/1/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in LOGON KB Support kb-support.This issue affects KB Support: from n/a through <= 1.6.7. | |
| Aplazada | Media (5.9) | 0.23% | — | Octrace SupportAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Octrace WordPress HelpDesk & Support Ticket System Plugin – Octrace Support octrace-support allows Stored XSS.This issue affects WordPress HelpDesk & Support Ticket System Plugin – Octrace Support: from n/a through <=… | |
| Aplazada | Media (5.5) | 0.27% | — | Rails ActivesupportAI | 9/1/2025 | 17/6/2026 | ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's possible for other users on the same system to read the contents of the temporary file. Attackers that have access to the… | |
| Aplazada | Media (5.3) | 0.92% | — | Rails ActivesupportAI | 9/1/2025 | 17/6/2026 | There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input. | |
| Aplazada | Media (4.3) | 0.29% | — | Themesupport Hide Category BY User Role FOR WoocommerceAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-role-for-woocommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through <= 2.1.1. | |
| Aplazada | Media (4.3) | 0.29% | — | Hive SupportAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Hive Support Hive Support hive-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hive Support: from n/a through <= 1.1.6. | |
| Aplazada | Media (6.4) | 0.31% | — | Viber Chat SupportAI | 7/1/2025 | 17/6/2026 | The Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vchat' shortcode in all versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping on user supplied… | |
| Analizada | Alta (8.8) | 0.55% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 25/12/2024 | 17/6/2026 | Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges… | |
| Analizada | Alta (7.2) | 14% | ⚠ Explotación activa | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 18/12/2024 | 17/6/2026 | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user. | |
| Aplazada | Alta (8.5) | 0.49% | — | Ydesignservices YDS Support Ticket SystemAI | 18/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ydesignservices YDS Support Ticket System yds-support-ticket-system allows SQL Injection.This issue affects YDS Support Ticket System: from n/a through <= 1.0. | |
| Analizada | Crítica (9.8) | 87% | ⚠ Explotación activa💥 Exploit | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 17/12/2024 | 17/6/2026 | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user. | |
| Aplazada | Media (4.3) | 0.24% | — | Hive SupportAI | 13/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hive Support Hive Support hive-support allows Cross Site Request Forgery.This issue affects Hive Support: from n/a through <= 1.1.2. | |
| Aplazada | Alta (8.5) | 0.50% | — | Hive SupportAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hive Support Hive Support hive-support allows SQL Injection.This issue affects Hive Support: from n/a through <= 1.1.2. | |
| Aplazada | Media (6.5) | 0.60% | — | Awesomesupport Awesome SupportAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.3.1. | |
| Aplazada | Alta (7.1) | 0.44% | — | Octrace SupportAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Octrace WordPress HelpDesk & Support Ticket System Plugin – Octrace Support octrace-support allows Reflected XSS.This issue affects WordPress HelpDesk & Support Ticket System Plugin – Octrace Support: from n/a through… | |
| Aplazada | Media (6.5) | 0.32% | — | Ilghera Woocommerce Support SystemAI | 13/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ilGhera Woocommerce Support System allows Cross Site Request Forgery.This issue affects Woocommerce Support System: from n/a through 1.2.2. | |
| Aplazada | Media (5.3) | 0.53% | — | Wponlinesupport Essential Plugin AccordionAIWponlinesupport Accordion SliderAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Accordion and Accordion Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion and Accordion Slider: from n/a through 1.2.4. | |
| Aplazada | Media (4.3) | 0.46% | — | Portfolio AND ProjectsAIWponlinesupport WP OnlinesupportAIEssentialplugin Essential PluginAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Portfolio and Projects allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio and Projects: from n/a through 1.3.7. | |
| Modificada | Media (6.5) | 0.55% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.7. | |
| Modificada | Media (5.4) | 0.48% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.10. | |
| Modificada | Media (5.4) | 0.48% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.4. | |
| Aplazada | Media (5.3) | 0.42% | — | Wponlinesupport Featured Post CreativeAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7. | |
| Aplazada | Media (5.3) | 0.58% | — | Wponsupport WP OnsupportAIEssentialplugin Album AND Image Gallery Plus LightboxAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Album and Image Gallery plus Lightbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Album and Image Gallery plus Lightbox: from n/a through 1.6.2. |