Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.26% | — | Ilghera Support SystemAI | 13/5/2026 | 30/9/2026 | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ticket_content_callback' function in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to view any support ticket… | |
| Modificada | Crítica (9.4) | 0.69% | — | Oretnom23 Customer Support System | 18/2/2026 | 8/9/2026 | SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform… | |
| Aplazada | Media (5.3) | 0.28% | — | Ilghera Support System FOR WoocommerceAI | 6/1/2026 | 17/6/2026 | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'delete_single_ticket_callback' and 'change_ticket_status_callback' functions in all versions up to, and including, 1.2.6. This makes it possible for… | |
| Aplazada | Alta (8.7) | 0.39% | — | Jheng GAO Student Learning Assessment AND Support SystemAI | 15/12/2025 | 17/6/2026 | Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain test accounts and password. | |
| Analizada | Media (4.8) | 0.39% | — | Oretnom23 Customer Support System | 16/6/2025 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote attackers to execute arbitrary code via the page parameter. | |
| Analizada | Alta (8.7) | 0.50% | — | Oretnom23 Customer Support System | 16/6/2025 | 17/6/2026 | SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the /customer_support/manage_user.php endpoint. | |
| Aplazada | Media (6.5) | 0.32% | — | Ilghera Woocommerce Support SystemAI | 13/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ilGhera Woocommerce Support System allows Cross Site Request Forgery.This issue affects Woocommerce Support System: from n/a through 1.2.2. | |
| Analizada | Alta (8.8) | 0.83% | — | Oretnom23 Customer Support System | 21/3/2024 | 17/6/2026 | Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators. | |
| Analizada | Media (5.4) | 0.48% | — | Oretnom23 Customer Support System | 7/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and address parameters. | |
| Analizada | Media (5.4) | 0.45% | — | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer. | |
| Analizada | Media (5.4) | 0.47% | — | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the subject parameter at /customer_support/index.php?page=new_ticket. | |
| Analizada | Media (6.1) | 0.45% | — | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customer_support/index.php?page=customer_list. | |
| Analizada | Media (6.1) | 0.45% | — | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list. | |
| Analizada | Media (6.1) | 0.43% | — | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list. | |
| Analizada | Crítica (9.8) | 0.82% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket. | |
| Analizada | Media (4.3) | 0.52% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer. | |
| Analizada | Alta (7.3) | 0.46% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php. | |
| Analizada | Alta (8.8) | 0.76% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user. | |
| Analizada | Crítica (9.8) | 1.1% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login. | |
| Analizada | Alta (8.8) | 0.76% | — | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php. | |
| Analizada | Alta (7.5) | 0.77% | — | Oretnom23 Customer Support System | 1/3/2024 | 17/6/2026 | A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization. | |
| Analizada | Media (4.9) | 0.73% | — | Oretnom23 Customer Support System | 1/3/2024 | 17/6/2026 | A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php. | |
| Analizada | Alta (7.5) | 0.49% | — | Open-mss Mission Support System | 15/2/2024 | 17/6/2026 | MSS (Mission Support System) is an open source package designed for planning atmospheric research flights. In file: `index.py`, there is a method that is vulnerable to path manipulation attack. By modifying file paths, an attacker can acquire sensitive information from different resources. The `filename` variable is… | |
| Modificada | Media (5.5) | 0.23% | — | Cals-ed Electronic Delivery Check SystemCals-ed Electronic Delivery Item Inspection Support System | 24/1/2024 | 17/6/2026 | Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier improperly restrict XML external entity… | |
| Modificada | Alta (8.8) | 14% | — | Customer Support System Project Customer Support System | 29/12/2023 | 17/6/2026 | Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name. |