Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.20% | — | Awesomesupport Awesome SupportAI | 1/10/2026 | 1/10/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.24% | — | Awesomesupport Awesome SupportAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions. | |
| Aplazada | Media (4.3) | 0.24% | — | Awesomesupport Awesome SupportAI | 9/9/2026 | 11/9/2026 | The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or… | |
| Aplazada | Media (5.3) | 0.44% | — | Awesomesupport Awesome SupportAI | 8/4/2026 | 25/7/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the authenticated user has permission to view the specific… | |
| Aplazada | Media (6.5) | 0.40% | — | Awesomesupport Awesome SupportAI | 16/1/2026 | 17/6/2026 | The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the 'wpas_do_mr_activate_user' function not verifying that a user has permission to modify other users' roles,… | |
| Aplazada | Alta (7.2) | 0.47% | — | Awesomesupport Awesome SupportAI | 22/9/2025 | 30/9/2026 | Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome Support: from n/a through <= 6.3.5. | |
| Aplazada | Media (5.3) | 0.29% | — | Awesomesupport Awesome SupportAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6. | |
| Aplazada | Alta (7.5) | 0.65% | — | Awesomesupport Awesome SupportAI | 1/4/2025 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Aplazada | Media (5.5) | 0.27% | — | Rails ActivesupportAI | 9/1/2025 | 17/6/2026 | ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's possible for other users on the same system to read the contents of the temporary file. Attackers that have access to the… | |
| Aplazada | Media (5.3) | 0.92% | — | Rails ActivesupportAI | 9/1/2025 | 17/6/2026 | There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input. | |
| Aplazada | Media (4.3) | 0.29% | — | Themesupport Hide Category BY User Role FOR WoocommerceAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-role-for-woocommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through <= 2.1.1. | |
| Aplazada | Media (6.5) | 0.60% | — | Awesomesupport Awesome SupportAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.3.1. | |
| Aplazada | Media (5.3) | 0.53% | — | Wponlinesupport Essential Plugin AccordionAIWponlinesupport Accordion SliderAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Accordion and Accordion Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion and Accordion Slider: from n/a through 1.2.4. | |
| Aplazada | Media (4.3) | 0.46% | — | Portfolio AND ProjectsAIWponlinesupport WP OnlinesupportAIEssentialplugin Essential PluginAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Portfolio and Projects allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio and Projects: from n/a through 1.3.7. | |
| Modificada | Media (6.5) | 0.55% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.7. | |
| Modificada | Media (5.4) | 0.48% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.10. | |
| Modificada | Media (5.4) | 0.48% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.4. | |
| Aplazada | Media (5.3) | 0.42% | — | Wponlinesupport Featured Post CreativeAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7. | |
| Aplazada | Alta (8.5) | 0.54% | — | Wponlinesupport Essential Plugin Timeline AND History SliderAI | 19/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essential Plugin Timeline and History slider allows PHP Local File Inclusion.This issue affects Timeline and History slider: from n/a through 2.3. | |
| Modificada | Alta (7.3) | 0.30% | — | Awesomesupport Awesome Support Wordpress Helpdesk & Support | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5. | |
| Modificada | Alta (8.8) | 0.30% | — | Getawesomesupport Awesome Support | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7. | |
| Modificada | Media (5.4) | 0.31% | — | Getawesomesupport Awesome Support | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.6. | |
| Modificada | Crítica (9.8) | 0.40% | — | Getawesomesupport Awesome Support | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7. | |
| Modificada | Media (5.3) | 0.40% | — | Getawesomesupport Awesome Support | 10/2/2024 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Modificada | Media (4.3) | 0.43% | — | Getawesomesupport Awesome Support | 10/2/2024 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level… |