Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.29%—Django-helpdeskAI13/8/20269/9/2026
django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments through public ticket submission channels. Attackers can exploit the lack of…
AnalizadaMedia (4.4)0.21%—Django-helpdesk Project Django-helpdesk31/5/202517/6/2026
django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.
ModificadaCrítica (9.6)1.4%—Django-helpdesk Project Django-helpdesk1/12/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (5.4)0.80%—Django-helpdesk Project Django-helpdesk19/11/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (6.1)1.0%—Django-helpdesk Project Django-helpdesk13/11/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')