Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 304 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

30 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.20%—Awesomesupport Awesome SupportAI1/10/20261/10/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.24%—Awesomesupport Awesome SupportAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
AplazadaMedia (4.3)0.24%—Awesomesupport Awesome SupportAI9/9/202611/9/2026
The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or…
AplazadaMedia (5.3)0.44%—Awesomesupport Awesome SupportAI8/4/202625/7/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the authenticated user has permission to view the specific…
AplazadaMedia (6.5)0.40%—Awesomesupport Awesome SupportAI16/1/202617/6/2026
The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the 'wpas_do_mr_activate_user' function not verifying that a user has permission to modify other users' roles,…
AplazadaAlta (7.2)0.47%—Awesomesupport Awesome SupportAI22/9/202530/9/2026
Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome Support: from n/a through <= 6.3.5.
AplazadaMedia (5.3)0.29%—Awesomesupport Awesome SupportAI9/9/202517/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6.
AplazadaAlta (7.5)0.65%—Awesomesupport Awesome SupportAI1/4/202517/6/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the…
AplazadaMedia (6.5)0.60%—Awesomesupport Awesome SupportAI13/12/202417/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.3.1.
ModificadaMedia (6.5)0.55%—Getawesomesupport Awesome Support9/12/202417/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.7.
ModificadaMedia (5.4)0.48%—Getawesomesupport Awesome Support9/12/202417/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.10.
ModificadaMedia (5.4)0.48%—Getawesomesupport Awesome Support9/12/202417/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.4.
ModificadaAlta (7.3)0.30%—Awesomesupport Awesome Support Wordpress Helpdesk & Support12/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.
ModificadaAlta (8.8)0.30%—Getawesomesupport Awesome Support10/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.
ModificadaMedia (5.4)0.31%—Getawesomesupport Awesome Support9/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.6.
ModificadaCrítica (9.8)0.40%—Getawesomesupport Awesome Support9/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.
ModificadaMedia (5.3)0.40%—Getawesomesupport Awesome Support10/2/202417/6/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and…
ModificadaMedia (4.3)0.43%—Getawesomesupport Awesome Support10/2/202417/6/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level…
ModificadaAlta (8.8)0.63%—Getawesomesupport Awesome Support10/2/202417/6/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
ModificadaAlta (8.8)0.22%—Getawesomesupport Awesome Support5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.5.
ModificadaAlta (8.8)0.25%—Getawesomesupport Awesome Support30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.
ModificadaAlta (8.1)0.66%—Getawesomesupport Awesome Support6/11/202317/6/2026
The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.
ModificadaMedia (6.1)0.40%—Getawesomesupport Awesome Support6/11/202317/6/2026
The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaMedia (4.3)0.40%—Getawesomesupport Awesome Support6/11/202317/6/2026
The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.
ModificadaMedia (6.5)0.75%—Getawesomesupport Awesome Support28/11/202217/6/2026
The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector