Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1338▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.4) | 0.69% | — | Oretnom23 Customer Support System | 18/2/2026 | 8/9/2026 | SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform… | |
| Analizada | Media (4.8) | 0.39% | — | Oretnom23 Customer Support System | 16/6/2025 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote attackers to execute arbitrary code via the page parameter. | |
| Analizada | Alta (8.7) | 0.50% | — | Oretnom23 Customer Support System | 16/6/2025 | 17/6/2026 | SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the /customer_support/manage_user.php endpoint. | |
| Analizada | Alta (8.8) | 0.83% | — | Oretnom23 Customer Support System | 21/3/2024 | 17/6/2026 | Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators. | |
| Analizada | Media (5.4) | 0.48% | — | Oretnom23 Customer Support System | 7/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and address parameters. | |
| Analizada | Media (5.4) | 0.45% | — | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer. | |
| Analizada | Media (5.4) | 0.47% | — | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the subject parameter at /customer_support/index.php?page=new_ticket. | |
| Analizada | Media (6.1) | 0.45% | — | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customer_support/index.php?page=customer_list. | |
| Analizada | Media (6.1) | 0.45% | — | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list. | |
| Analizada | Media (6.1) | 0.43% | — | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list. | |
| Analizada | Crítica (9.8) | 0.82% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket. | |
| Analizada | Media (4.3) | 0.52% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer. | |
| Analizada | Alta (7.3) | 0.46% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php. | |
| Analizada | Alta (8.8) | 0.76% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user. | |
| Analizada | Crítica (9.8) | 1.1% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login. | |
| Analizada | Alta (8.8) | 0.76% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php. | |
| Analizada | Alta (7.5) | 0.77% | — | Oretnom23 Customer Support System | 1/3/2024 | 17/6/2026 | A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization. | |
| Analizada | Media (4.9) | 0.73% | — | Oretnom23 Customer Support System | 1/3/2024 | 17/6/2026 | A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php. | |
| Modificada | Alta (8.8) | 14% | — | Customer Support System Project Customer Support System | 29/12/2023 | 17/6/2026 | Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name. | |
| Modificada | Alta (8.8) | 0.79% | — | Oretnom23 Customer Support System | 29/12/2023 | 17/6/2026 | Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject. |