Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.21% | — | GestsupAI | 28/9/2026 | 30/9/2026 | GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaScript that executes… | |
| Aplazada | Alta (7.1) | 0.24% | — | GestsupAI | 28/9/2026 | 1/10/2026 | GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks. | |
| Aplazada | Media (5.3) | 0.21% | — | GestsupAI | 28/9/2026 | 30/9/2026 | GestSup versions before 3.2.61 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthenticated attackers to store arbitrary JavaScript in ticket descriptions and replies. Attackers can send emails to the monitored mailbox containing script tags and event handlers that execute in… | |
| Aplazada | Crítica (9.2) | 0.58% | — | GestsupAI | 25/9/2026 | 30/9/2026 | GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket… | |
| Analizada | Alta (8.8) | 0.68% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. | |
| Analizada | Media (6.8) | 0.35% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. | |
| Analizada | Media (6.8) | 0.38% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. | |
| Analizada | Media (4.3) | 0.25% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. | |
| Analizada | Alta (8) | 0.41% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. | |
| Aplazada | Media (6.4) | 0.28% | — | SmartsuppAI | 19/2/2026 | 17/6/2026 | The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.1) | 0.29% | — | Gestsup | 9/1/2026 | 17/6/2026 | GestSup versions prior to 3.2.60 contain a pre-authentication stored cross-site scripting (XSS) vulnerability in the API error logging functionality. By sending an API request with a crafted X-API-KEY header value (for example, to /api/v1/ticket.php), an unauthenticated attacker can cause attacker-controlled… | |
| Analizada | Alta (7.5) | 0.32% | — | Gestsup | 9/1/2026 | 17/6/2026 | GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, search, or sort assets are incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries.… | |
| Analizada | Alta (7.7) | 0.32% | — | Gestsup | 9/1/2026 | 17/6/2026 | GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket creation is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation… | |
| Analizada | Alta (7.7) | 0.32% | — | Gestsup | 9/1/2026 | 17/6/2026 | GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation can result in unauthorized… | |
| Analizada | Alta (8.9) | 0.24% | — | Gestsup | 9/1/2026 | 17/6/2026 | GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the victim's privileges. This can be exploited to… | |
| Aplazada | Alta (8.7) | 1.0% | — | Netsupport ManagerAI | 15/12/2025 | 17/6/2026 | NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary locations on the server. This can be… | |
| Aplazada | Alta (8.7) | 0.40% | — | Netsupport ManagerAI | 15/12/2025 | 17/6/2026 | NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote… | |
| Aplazada | Alta (8.4) | 0.18% | — | Netsupport ManagerAI | 15/12/2025 | 5/10/2026 | NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access to a deployed client configuration file can decode the stored value to recover the… | |
| Aplazada | Alta (8.8) | 0.50% | — | Netsupport ManagerAI | 30/8/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially leak a limited amount of memory. | |
| Aplazada | Crítica (9.3) | 0.66% | — | Netsupport ManagerAI | 30/8/2025 | 17/6/2026 | A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code. | |
| Analizada | Media (5.3) | 0.26% | — | Progress Whatsup Gold | 14/4/2025 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup. | |
| Analizada | Media (5.1) | 0.24% | — | Egoist Tsup | 3/3/2025 | 17/6/2026 | A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components | |
| Aplazada | Media (6.5) | 0.22% | — | Smartsupp Live ChatAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Smartsupp Smartsupp – live chat, chatbots, AI and lead generation smartsupp-live-chat allows Cross Site Request Forgery.This issue affects Smartsupp – live chat, chatbots, AI and lead generation: from n/a through <= 3.6. | |
| Analizada | Crítica (9.6) | 6.8% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API. | |
| Analizada | Alta (7.5) | 9.7% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings. |