Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.47% | — | Wpbot AI Chatbot FOR Live Support Lead Generation AI ServicesAI | 28/7/2026 | 28/7/2026 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and… | |
| Aplazada | Alta (7.5) | 0.45% | — | Videowhisper Contact FormsAIVideowhisper Live SupportAIVideowhisper CRMAIVideowhisper Video MessagesAI+1 | 17/10/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in videowhisper Contact Forms, Live Support, CRM, Video Messages live-support-tickets allows Retrieve Embedded Sensitive Data.This issue affects Contact Forms, Live Support, CRM, Video Messages: from n/a through <= 1.10.2. | |
| Modificada | Alta (8.8) | 0.82% | — | Onwebchat Live Chat - Live Support | 15/10/2020 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (4.3) | 10% | — | Clickdesk Live Support-live Chat Plugin | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.5% | — | Xigla Absolute Live Support .net | 14/7/2009 | 16/6/2026 | Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | |
| Modificada | Alta (7.5) | 3.4% | — | V3chat V3 Chat Live Support | 31/12/2008 | 16/6/2026 | admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. | |
| Modificada | Baja (3.5) | 0.89% | — | Xigla Absolute Live Support XE | 18/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors ("all fields"). | |
| Modificada | Media (6.5) | 0.99% | — | Xigla Absolute Live Support XE | 18/6/2008 | 16/6/2026 | SQL injection vulnerability in search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter. | |
| Modificada | Alta (10) | 4.5% | — | Alstrasoft Live Support | 21/5/2007 | 16/6/2026 | AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php. | |
| Modificada | Alta (7.5) | 1.2% | — | ASP Scripter Easy PortalASP Scripter Live Support | 16/11/2006 | 16/6/2026 | SQL injection vulnerability in cpLogin.asp in ASP Scripter Easy Portal 1.4 and Live Support 1.3 allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Xigla Absolute Live Support XE | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field. |