Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2538▼ 392 respecto a la semana anterior
Críticas / altas1301▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)7.4%—Mods-for-hesk Mods FOR Hesk9/7/202017/6/2026
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of improper access control of uploaded resources. This might be exploitable in conjunction with CVE-2020-13992 by an unauthenticated attacker.
ModificadaAlta (7.5)2.1%—Mods-for-hesk Mods FOR Hesk9/7/202017/6/2026
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote unauthenticated attackers to retrieve information from the database via a ticket.
ModificadaMedia (6.1)1.2%—Mods-for-hesk Mods FOR Hesk9/7/202017/6/2026
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attackers to abuse a helpdesk user's logged in session. A user with sufficient privileges to change their login-page image must open a crafted ticket.
ModificadaMedia (6.1)0.64%—Hesk7/6/202017/6/2026
HESK before 3.1.10 allows reflected XSS.
ModificadaMedia (4.3)0.97%—Hesk1/1/201516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in HESK before 2.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) hesk_settings[tmp_title] or (2) hesklang[ENCODING] parameter to inc/header.inc.php; the hesklang[attempt] parameter to (3) inc/assignment_search.inc.php, (4)…
ModificadaMedia (5)1.3%—Hesk23/9/201116/6/2026
Hesk 2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/footer.inc.php and certain other files.
ModificadaAlta (7.5)3.0%—Helpdesk Software Hesk21/9/200516/6/2026
Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie.
ModificadaAlta (7.5)1.6%—Helpdesk Software Hesk8/9/200516/6/2026
Helpdesk software Hesk 0.92 does not properly verify usernames and passwords, which allows remote attackers to bypass authentication via a direct request to admin_main.php.