Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2625▼ 312 respecto a la semana anterior
Críticas / altas1347▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.64%—Uvdesk Community SkeletonAI16/9/202622/9/2026
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control…
AplazadaAlta (7.1)0.36%—Uvdesk Community SkeletonAI2/4/202417/6/2026
Improper Privilege Management in uvdesk/community-skeleton
ModificadaCrítica (9.8)1.2%—Uvdesk Community-skeleton23/10/202317/6/2026
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.
ModificadaMedia (6.1)0.69%—Uvdesk Community-skeleton4/4/202317/6/2026
Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket.
ModificadaAlta (8.8)1.6%—Uvdesk Community-skeleton4/4/202317/6/2026
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.
ModificadaMedia (4.8)0.40%—Uvdesk Community-skeleton6/3/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.