Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.40% | — | Support GenixAI | 1/9/2026 | 2/9/2026 | The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to… | |
| Aplazada | Media (5.3) | 0.71% | — | Support GenixAI | 1/8/2026 | 26/8/2026 | The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthenticated attackers to read arbitrary files with an allowlisted extension — including other users' private ticket attachments — from the server. | |
| Aplazada | Baja (3.7) | 0.26% | — | Support GenixAI | 31/7/2026 | 26/8/2026 | The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments. | |
| Aplazada | Media (5.3) | 0.22% | — | Devitems Support GenixAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Support Genix: from n/a through <= 1.4.23. | |
| Aplazada | Media (4.3) | 0.49% | — | Devitems Support GenixAI | 27/3/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Support Genix: from n/a through <= 1.4.11. | |
| Aplazada | Crítica (9.9) | 0.76% | — | Support GenixAI | 18/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3. |