Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)298▼ 212 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.51% | — | Faveo HelpdeskAI | 24/8/2026 | 27/8/2026 | A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.72% | — | Faveo HelpdeskAI | 24/8/2026 | 26/8/2026 | A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The… | |
| Aplazada | Media (6.5) | 0.37% | — | Ladybirdweb Faveo HelpdeskAI | 11/8/2026 | 3/9/2026 | A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access… | |
| Analizada | Media (5.4) | 0.45% | — | Ladybirdweb Faveo Helpdesk | 1/11/2024 | 17/6/2026 | An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields | |
| Aplazada | Alta (8.2) | 0.38% | — | Ladybird WEB Solution Faveo-helpdeskAI | 22/10/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file. | |
| Modificada | Media (5.4) | 0.47% | — | Ladybirdweb Faveo Helpdesk | 24/6/2023 | 17/6/2026 | Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the application. This occurs because the application is vulnerable to stored XSS. | |
| Modificada | Alta (8.8) | 0.80% | — | Ladybirdweb Faveo Helpdesk | 24/3/2023 | 17/6/2026 | Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection. | |
| Modificada | Media (6.5) | 1.1% | — | Ladybirdweb Faveo Servicedesk | 24/3/2023 | 17/6/2026 | Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack. | |
| Modificada | Media (6.1) | 0.84% | — | Faveohelpdesk Faveo | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter. | |
| Modificada | Alta (8) | 2.2% | 💥 Exploit | Ladybirdweb Faveo Helpdesk | 6/4/2017 | 17/6/2026 | public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. |