Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.17%—Majesticsupport Majestic SupportAI1/10/20261/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
AplazadaMedia (5.3)0.18%—Majesticsupport Majestic SupportAI1/10/20261/10/2026
Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
AplazadaMedia (6.5)0.59%—Majesticsupport Majestic SupportAI11/7/202613/7/2026
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter in all versions up to, and including, 1.1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaMedia (5.4)0.23%—Majesticsupport Majestic SupportAI26/6/202626/6/2026
Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.
AplazadaMedia (5.3)0.26%—Majesticsupport Majestic SupportAI15/4/202617/6/2026
Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.2.
AplazadaAlta (7.5)0.40%—Majesticsupport Majestic SupportAI29/10/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File Inclusion.This issue affects Majestic Support: from n/a through <= 1.0.7.
AplazadaMedia (5.3)0.29%—Majesticsupport Majestic SupportAI9/9/202517/6/2026
Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.1.0.
AplazadaCrítica (9.3)0.35%—Majesticsupport Majestic SupportAI23/5/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support Majestic Support majestic-support allows SQL Injection.This issue affects Majestic Support: from n/a through <= 1.1.0.
AplazadaMedia (5.3)0.26%—Majesticsupport Majestic SupportAI19/5/202517/6/2026
Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.0.
AplazadaAlta (8.1)0.80%—Majesticsupport Majestic SupportAI25/2/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File Inclusion.This issue affects Majestic Support: from n/a through <= 1.0.6.
AnalizadaMedia (4.3)0.33%—Majesticsupport Majestic Support12/2/202517/6/2026
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validation on a user controlled key. This makes it possible for…
AnalizadaAlta (7.5)0.50%—Majesticsupport Majestic Support12/2/202517/6/2026
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the 'majesticsupportdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored…