Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 215 respecto a la semana anterior
Críticas / altas1379▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.21% | — | Django-helpdesk Project Django-helpdesk | 31/5/2025 | 17/6/2026 | django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py. | |
| Modificada | Crítica (9.6) | 1.4% | — | Django-helpdesk Project Django-helpdesk | 1/12/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.4) | 0.80% | — | Django-helpdesk Project Django-helpdesk | 19/11/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.1) | 1.0% | — | Django-helpdesk Project Django-helpdesk | 13/11/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Alta (8.1) | 7.4% | — | Helpdeskpro Helpdesk PRO | 20/9/2017 | 17/6/2026 | The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task. | |
| Modificada | Alta (7.5) | 57% | — | Helpdesk PRO Project Helpdesk PRO | 20/9/2017 | 17/6/2026 | Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task. | |
| Modificada | Crítica (9.8) | 4.2% | — | Helpdesk PRO Project Helpdesk PRO | 20/9/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter. | |
| Modificada | Media (5.4) | 2.9% | — | Helpdesk PRO Project Helpdesk PRO | 20/9/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message. | |
| Modificada | Media (5.3) | 9.6% | — | Helpdesk PRO Project Helpdesk PRO | 18/8/2017 | 17/6/2026 | The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}. |