Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

514 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.24%—Pc-helper Wireless IO Dio-0404ry-lwfAIPc-helper Wireless IO Dio-0404ry-lwf-usAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaBaja (2)0.51%—Faveo HelpdeskAI24/8/202627/8/2026
A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been…
AplazadaMedia (5.5)0.72%—Faveo HelpdeskAI24/8/202626/8/2026
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The…
AplazadaBaja (1.9)1.1%—Sworddut Mcp-ffmpeg-helperAI24/8/202626/8/2026
A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of the argument format results in os command injection. Attacking locally is a requirement. The exploit is now public…
AnalizadaMedia (5.5)0.98%—Microsoft Remote Help20/8/202626/8/2026
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
AnalizadaAlta (7.1)0.46%—Microsoft Remote Help20/8/202626/8/2026
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
AplazadaMedia (5.3)0.29%—Django-helpdeskAI13/8/20269/9/2026
django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments through public ticket submission channels. Attackers can exploit the lack of…
AplazadaAlta (8.2)0.33%—Matbao WP Helper PremiumAI13/8/202626/8/2026
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary…
AplazadaMedia (6.5)0.37%—Ladybirdweb Faveo HelpdeskAI11/8/20263/9/2026
A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access…
AplazadaMedia (6.5)0.34%—Jshelpdesk JS Help DeskAI31/7/202626/8/2026
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.
AplazadaMedia (6.5)0.37%—Jshelpdesk JS Help DeskAI31/7/202626/8/2026
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.
AplazadaAlta (7.5)0.41%—Jshelpdesk JS Help DeskAI31/7/202626/8/2026
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users'…
AplazadaMedia (4.3)0.25%—Jshelpdesk JS Help DeskAI31/7/202626/8/2026
The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.
AplazadaMedia (6.5)0.37%—Jshelpdesk JS Help DeskAI31/7/202626/8/2026
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.
AnalizadaCrítica (9.8)1.0%—Solarwinds WEB Help Desk30/7/202617/8/2026
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
AplazadaMedia (4.3)0.14%—WP Accessibility HelperAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
AplazadaCrítica (9.8)0.95%—Customer Support Ticket System HelpdeskAI23/7/202623/7/2026
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated…
AplazadaMedia (6.4)0.35%—ChathelpAI17/7/202617/7/2026
The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it…
AnalizadaAlta (7.8)0.30%—Microsoft Remote Help14/7/202624/7/2026
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
AplazadaAlta (7.5)0.66%—Chat HelpAI10/7/202610/7/2026
The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing any authentication and…
AplazadaAlta (7.5)0.43%—Openai Chatbot FOR Wordpress HelperAI2/7/202630/9/2026
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
AplazadaMedia (5.3)0.31%—Jshelpdesk JS Help DeskAI26/6/202626/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.
AplazadaAlta (7.7)0.47%—Jshelpdesk JS Help DeskAI25/6/202625/6/2026
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
AplazadaAlta (7.4)0.28%—Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI15/6/202617/6/2026
Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat Buttons <= 1.4.8 versions.
AplazadaAlta (8.5)0.36%—Elex Wordpress Helpdesk & Customer Ticketing SystemAI15/6/202617/6/2026
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.