Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

104 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.21%—GestsupAI28/9/202630/9/2026
GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaScript that executes…
AplazadaAlta (7.1)0.24%—GestsupAI28/9/20261/10/2026
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
AplazadaMedia (5.3)0.21%—GestsupAI28/9/202630/9/2026
GestSup versions before 3.2.61 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthenticated attackers to store arbitrary JavaScript in ticket descriptions and replies. Attackers can send emails to the monitored mailbox containing script tags and event handlers that execute in…
AplazadaCrítica (9.2)0.58%—GestsupAI25/9/202630/9/2026
GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket…
AnalizadaAlta (8.8)0.68%—Progress Whatsup Gold12/8/20262/9/2026
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
AnalizadaMedia (6.8)0.35%—Progress Whatsup Gold12/8/20262/9/2026
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
AnalizadaMedia (6.8)0.38%—Progress Whatsup Gold12/8/20262/9/2026
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
AnalizadaMedia (4.3)0.25%—Progress Whatsup Gold12/8/20262/9/2026
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
AnalizadaAlta (8)0.41%—Progress Whatsup Gold12/8/20262/9/2026
In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.
AplazadaMedia (6.4)0.28%—SmartsuppAI19/2/202617/6/2026
The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.1)0.29%—Gestsup9/1/202617/6/2026
GestSup versions prior to 3.2.60 contain a pre-authentication stored cross-site scripting (XSS) vulnerability in the API error logging functionality. By sending an API request with a crafted X-API-KEY header value (for example, to /api/v1/ticket.php), an unauthenticated attacker can cause attacker-controlled…
AnalizadaAlta (7.5)0.32%—Gestsup9/1/202617/6/2026
GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, search, or sort assets are incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries.…
AnalizadaAlta (7.7)0.32%—Gestsup9/1/202617/6/2026
GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket creation is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation…
AnalizadaAlta (7.7)0.32%—Gestsup9/1/202617/6/2026
GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation can result in unauthorized…
AnalizadaAlta (8.9)0.24%—Gestsup9/1/202617/6/2026
GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the victim's privileges. This can be exploited to…
AplazadaAlta (8.7)1.0%—Netsupport ManagerAI15/12/202517/6/2026
NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary locations on the server. This can be…
AplazadaAlta (8.7)0.40%—Netsupport ManagerAI15/12/202517/6/2026
NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote…
AplazadaAlta (8.4)0.18%—Netsupport ManagerAI15/12/20255/10/2026
NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access to a deployed client configuration file can decode the stored value to recover the…
AplazadaAlta (8.8)0.50%—Netsupport ManagerAI30/8/202517/6/2026
A stack-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially leak a limited amount of memory.
AplazadaCrítica (9.3)0.66%—Netsupport ManagerAI30/8/202517/6/2026
A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code.
AnalizadaMedia (5.3)0.26%—Progress Whatsup Gold14/4/202517/6/2026
In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.
AnalizadaMedia (5.1)0.24%—Egoist Tsup3/3/202517/6/2026
A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components
AplazadaMedia (6.5)0.22%—Smartsupp Live ChatAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Smartsupp Smartsupp – live chat, chatbots, AI and lead generation smartsupp-live-chat allows Cross Site Request Forgery.This issue affects Smartsupp – live chat, chatbots, AI and lead generation: from n/a through <= 3.6.
AnalizadaCrítica (9.6)6.8%—Progress Whatsup Gold31/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
AnalizadaAlta (7.5)9.7%—Progress Whatsup Gold31/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.