Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | 0.20% | — | Uvdesk Support Center BundleAI | 2/10/2026 | 2/10/2026 | UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to… | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Event CenterCisco Webex Meeting Center+2 | 26/11/2019 | 17/6/2026 | A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA protection in certain URLs. An attacker could… | |
| Modificada | Alta (8.8) | 6.0% | — | Cisco Webex Event CenterCisco Webex Meeting CenterCisco Webex MeetingsCisco Webex Meetings Server+16 | 25/7/2017 | 17/6/2026 | A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco… | |
| Modificada | Media (4.3) | 3.0% | — | Isolsoft Support Center | 4/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | |
| Modificada | Alta (7.5) | 7.7% | — | Isolsoft Support Center | 4/1/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) newticket.php or (2) rempass.php, or a URL in the lang parameter in an adduser action to (3) index.php. NOTE: this can also be leveraged to… | |
| Modificada | Media (5) | 11% | — | Joomlashowroom PRO Desk Support Center | 20/2/2009 | 16/6/2026 | Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter to index.php. | |
| Modificada | Alta (9.4) | 3.4% | — | HP Help AND Support Center | 12/6/2007 | 16/6/2026 | Buffer overflow in Help and Support Center before 4.4 C on HP Windows systems allows remote attackers to read or write arbitrary files via unknown vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | Isolsoft Support Center | 26/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter. |