Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.17% | — | Majesticsupport Majestic SupportAI | 1/10/2026 | 1/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0. | |
| Aplazada | Media (5.3) | 0.18% | — | Majesticsupport Majestic SupportAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0. | |
| Aplazada | Media (6.5) | 0.59% | — | Majesticsupport Majestic SupportAI | 11/7/2026 | 13/7/2026 | The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter in all versions up to, and including, 1.1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (5.4) | 0.23% | — | Majesticsupport Majestic SupportAI | 26/6/2026 | 26/6/2026 | Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions. | |
| Aplazada | Media (5.3) | 0.26% | — | Majesticsupport Majestic SupportAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.5) | 0.40% | — | Majesticsupport Majestic SupportAI | 29/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File Inclusion.This issue affects Majestic Support: from n/a through <= 1.0.7. | |
| Aplazada | Media (5.3) | 0.29% | — | Majesticsupport Majestic SupportAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.1.0. | |
| Aplazada | Crítica (9.3) | 0.35% | — | Majesticsupport Majestic SupportAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support Majestic Support majestic-support allows SQL Injection.This issue affects Majestic Support: from n/a through <= 1.1.0. | |
| Aplazada | Media (5.3) | 0.26% | — | Majesticsupport Majestic SupportAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.0. | |
| Aplazada | Alta (8.1) | 0.80% | — | Majesticsupport Majestic SupportAI | 25/2/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File Inclusion.This issue affects Majestic Support: from n/a through <= 1.0.6. | |
| Analizada | Media (4.3) | 0.33% | — | Majesticsupport Majestic Support | 12/2/2025 | 17/6/2026 | The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validation on a user controlled key. This makes it possible for… | |
| Analizada | Alta (7.5) | 0.50% | — | Majesticsupport Majestic Support | 12/2/2025 | 17/6/2026 | The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the 'majesticsupportdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored… |