Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
–

790 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)——Majesticsupport Majestic SupportAI1/10/20261/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
AplazadaMedia (5.3)——Majesticsupport Majestic SupportAI1/10/20261/10/2026
Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
AplazadaMedia (6.4)——Awesomesupport Awesome SupportAI1/10/20261/10/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.25%—Awesomesupport Awesome SupportAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
AplazadaMedia (5.4)0.23%—Wpmanageninja Fluent SupportAI23/9/202623/9/2026
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
Pendiente de análisisAlta (7.3)0.11%—HP Support AssistantAI22/9/202629/9/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AplazadaMedia (5.3)0.34%—SupportcandyAI9/9/20269/9/2026
The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket.
AplazadaMedia (5.3)0.34%—SupportcandyAI9/9/20269/9/2026
The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket attachment download paths, allowing unauthenticated attackers to read protected customer-uploaded attachments by enumerating sequential attachment identifiers.
AplazadaMedia (4.3)0.24%—Awesomesupport Awesome SupportAI9/9/202611/9/2026
The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or…
Pendiente de análisisAlta (7.3)0.09%—HP Support AssistantAI3/9/20268/9/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AplazadaAlta (8.8)0.40%—Support GenixAI1/9/20262/9/2026
The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to…
AplazadaMedia (5.4)0.13%—Fluent Support PROAI24/8/202624/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
AplazadaMedia (5.4)0.23%—Fluent Support PROAI24/8/202624/8/2026
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
AplazadaAlta (8.2)0.41%—SupportcandyAI18/8/202620/8/2026
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
AplazadaMedia (6.1)0.25%—Benbodhi SVG SupportAI3/8/202626/8/2026
The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the…
AplazadaMedia (5.3)0.71%—Support GenixAI1/8/202626/8/2026
The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthenticated attackers to read arbitrary files with an allowlisted extension — including other users' private ticket attachments — from the server.
AplazadaBaja (3.8)0.26%—Wpmanageninja Fluent SupportAI1/8/202626/8/2026
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.
AplazadaBaja (3.7)0.26%—Support GenixAI31/7/202626/8/2026
The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.
AplazadaMedia (5.3)0.47%—Wpbot AI Chatbot FOR Live Support Lead Generation AI ServicesAI28/7/202628/7/2026
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and…
AplazadaMedia (6.4)0.34%—Wpmanageninja Fluent SupportAI24/7/202624/7/2026
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (6.5)0.22%—Wpmanageninja Fluent SupportAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
AplazadaCrítica (9.8)0.95%—Customer Support Ticket System HelpdeskAI23/7/202623/7/2026
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated…
AnalizadaMedia (5.4)0.23%—Oracle Isupport21/7/202619/8/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Call Back). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability…
AnalizadaAlta (8.1)0.36%—Oracle Customer Support21/7/20266/8/2026
Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Support. Successful…
AnalizadaAlta (7.4)0.32%—Oracle Isupport21/7/202631/7/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require…