Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.47%—Wpbot AI Chatbot FOR Live Support Lead Generation AI ServicesAI28/7/202628/7/2026
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and…
AplazadaAlta (7.5)0.45%—Videowhisper Contact FormsAIVideowhisper Live SupportAIVideowhisper CRMAIVideowhisper Video MessagesAI+117/10/202417/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in videowhisper Contact Forms, Live Support, CRM, Video Messages live-support-tickets allows Retrieve Embedded Sensitive Data.This issue affects Contact Forms, Live Support, CRM, Video Messages: from n/a through <= 1.10.2.
ModificadaAlta (8.8)0.82%—Onwebchat Live Chat - Live Support15/10/202017/6/2026
Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaMedia (4.3)10%—Clickdesk Live Support-live Chat Plugin20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)2.5%—Xigla Absolute Live Support .net14/7/200916/6/2026
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
ModificadaAlta (7.5)3.4%—V3chat V3 Chat Live Support31/12/200816/6/2026
admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.
ModificadaBaja (3.5)0.89%—Xigla Absolute Live Support XE18/6/200816/6/2026
Cross-site scripting (XSS) vulnerability in admin/search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors ("all fields").
ModificadaMedia (6.5)0.99%—Xigla Absolute Live Support XE18/6/200816/6/2026
SQL injection vulnerability in search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
ModificadaAlta (10)4.5%—Alstrasoft Live Support21/5/200716/6/2026
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php.
ModificadaAlta (7.5)1.2%—ASP Scripter Easy PortalASP Scripter Live Support16/11/200616/6/2026
SQL injection vulnerability in cpLogin.asp in ASP Scripter Easy Portal 1.4 and Live Support 1.3 allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaMedia (4.3)1.3%—Xigla Absolute Live Support XE28/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field.