Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

66 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.38%—Livehelperchat Live Helper ChatAI14/5/202617/6/2026
Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object fields, so the user can change the chat hash…
AplazadaMedia (5.5)0.47%—Bigsweetpotatostudio HyperchatAI28/4/202624/7/2026
A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/aiProxyMiddleware.mts of the component AI Proxy Middleware. Such manipulation of the argument baseurl leads to server-side request forgery. The attack…
AnalizadaMedia (4.9)0.34%—Livehelperchat Live Helper Chat26/2/202617/6/2026
Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreClassChat::hasAccessToRead()`, allowing operators to act on chats…
AplazadaMedia (6.9)0.28%—Livehelperchat Live Helper ChatAI28/1/202617/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the…
AnalizadaMedia (6.1)0.22%—Grabaperch Perch7/1/202617/6/2026
A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with administrative privileges can inject malicious JavaScript code into the “Help button url” setting within the admin panel. The injected payload is stored and executed when any authenticated user clicks the…
AnalizadaMedia (5.1)0.24%—Grabaperch Perch15/12/202517/6/2026
Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags that execute when the file is viewed, potentially stealing user session information or performing client-side attacks.
AnalizadaAlta (8.6)0.93%—Grabaperch Perch15/12/202517/6/2026
Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the assets management interface. Attackers can upload a malicious .phar file with embedded system command execution capabilities to execute arbitrary commands on the server.
AnalizadaMedia (6.5)1.5%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.
AnalizadaMedia (5.4)0.92%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.
AnalizadaMedia (5.4)0.92%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
AnalizadaMedia (5.4)0.92%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
AnalizadaMedia (5.4)0.95%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.
AnalizadaMedia (5.4)0.97%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.
AplazadaBaja (2)0.28%—Livehelperchat LHC PHP ResqueAI11/7/202517/6/2026
A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It has been classified as problematic. This affects an unknown part of the file /site_admin/lhcphpresque/list/ of the component List Handler. The manipulation of the argument queue name leads to cross…
AnalizadaMedia (6.8)0.29%—Keepersecurity Keeperchat9/6/202517/6/2026
An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module
AplazadaAlta (7.1)0.39%—Viperchill ViperbarAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in viperchill ViperBar viperbar allows Reflected XSS.This issue affects ViperBar: from n/a through <= 2.0.
AplazadaAlta (8.3)0.49%—Alpitronic HyperchargerAI15/5/202417/6/2026
If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administrator.
ModificadaMedia (5.3)0.47%—Themeperch Build & Control Block Pattern5/3/202417/6/2026
The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the settings_export() function in all versions up to, and including, 1.3.5.4. This makes it possible for unauthenticated attackers to export the plugin's…
AnalizadaCrítica (9.8)1.5%—Livehelperchat Live Helper Chat29/2/202417/6/2026
Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.
ModificadaCrítica (9.8)0.58%—Knowband Supercheckout19/10/202317/6/2026
KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout, Social Login & Mailchimp" (supercheckout), a guest can upload files with extensions .php
ModificadaCrítica (9.8)1.6%—Marketingheroes Sitesupercharger2/5/202217/6/2026
The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections
ModificadaMedia (6.1)0.65%—Livehelperchat Live Helper Chat29/4/202217/6/2026
Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute malicious JavaScript on the application.
ModificadaAlta (8.8)1.3%—Livehelperchat Live Helper Chat7/4/202217/6/2026
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
ModificadaMedia (6.1)0.73%—Livehelperchat Live Helper Chat6/4/202217/6/2026
XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
ModificadaAlta (8.2)0.56%—Livehelperchat Live Helper Chat5/4/202217/6/2026
Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.