Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.24% | — | Pc-helper Wireless IO Dio-0404ry-lwfAIPc-helper Wireless IO Dio-0404ry-lwf-usAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Baja (2) | 0.51% | — | Faveo HelpdeskAI | 24/8/2026 | 27/8/2026 | A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.72% | — | Faveo HelpdeskAI | 24/8/2026 | 26/8/2026 | A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The… | |
| Aplazada | Baja (1.9) | 1.1% | — | Sworddut Mcp-ffmpeg-helperAI | 24/8/2026 | 26/8/2026 | A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of the argument format results in os command injection. Attacking locally is a requirement. The exploit is now public… | |
| Analizada | Media (5.5) | 0.98% | — | Microsoft Remote Help | 20/8/2026 | 26/8/2026 | Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. | |
| Analizada | Alta (7.1) | 0.46% | — | Microsoft Remote Help | 20/8/2026 | 26/8/2026 | Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. | |
| Aplazada | Media (5.3) | 0.29% | — | Django-helpdeskAI | 13/8/2026 | 9/9/2026 | django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments through public ticket submission channels. Attackers can exploit the lack of… | |
| Aplazada | Alta (8.2) | 0.33% | — | Matbao WP Helper PremiumAI | 13/8/2026 | 26/8/2026 | The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary… | |
| Aplazada | Media (6.5) | 0.37% | — | Ladybirdweb Faveo HelpdeskAI | 11/8/2026 | 3/9/2026 | A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access… | |
| Aplazada | Media (6.5) | 0.34% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body. | |
| Aplazada | Media (6.5) | 0.37% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users. | |
| Aplazada | Alta (7.5) | 0.41% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users'… | |
| Aplazada | Media (4.3) | 0.25% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site. | |
| Aplazada | Media (6.5) | 0.37% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets. | |
| Analizada | Crítica (9.8) | 1.0% | — | Solarwinds WEB Help Desk | 30/7/2026 | 17/8/2026 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled. | |
| Aplazada | Media (4.3) | 0.14% | — | WP Accessibility HelperAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | |
| Aplazada | Crítica (9.8) | 0.95% | — | Customer Support Ticket System HelpdeskAI | 23/7/2026 | 23/7/2026 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.35% | — | ChathelpAI | 17/7/2026 | 17/7/2026 | The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Remote Help | 14/7/2026 | 24/7/2026 | Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (7.5) | 0.66% | — | Chat HelpAI | 10/7/2026 | 10/7/2026 | The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing any authentication and… | |
| Aplazada | Alta (7.5) | 0.43% | — | Openai Chatbot FOR Wordpress HelperAI | 2/7/2026 | 30/9/2026 | Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Jshelpdesk JS Help DeskAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions. | |
| Aplazada | Alta (7.7) | 0.47% | — | Jshelpdesk JS Help DeskAI | 25/6/2026 | 25/6/2026 | Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions. | |
| Aplazada | Alta (7.4) | 0.28% | — | Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Elex Wordpress Helpdesk & Customer Ticketing SystemAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions. |