Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.3)0.20%—Uvdesk Support Center BundleAI2/10/20262/10/2026
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to…
AplazadaAlta (8.6)0.44%—Uvdesk Core-frameworkAI21/9/202622/9/2026
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full…
AplazadaMedia (5.3)0.30%—Uvdesk Core-frameworkAI21/9/202622/9/2026
UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not…
AplazadaMedia (5.1)0.18%—Uvdesk Core-frameworkAISwiftmailerAI21/9/202624/9/2026
UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members…
AplazadaCrítica (9.3)0.64%—Uvdesk Community SkeletonAI16/9/202622/9/2026
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control…
ModificadaMedia (5.4)0.31%—Liveboxcloud Vdesk10/6/202417/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't properly check parameters, sent in HTTP requests as input, before saving…
ModificadaMedia (6.5)0.50%—Liveboxcloud Vdesk10/6/202417/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a user to generate or regenerate the backup codes before checking the…
ModificadaAlta (8.8)0.75%—Liveboxcloud Vdesk28/5/202417/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare web site section. A remote user, authenticated to the product, can arbitrarily upload potentially dangerous files without restrictions.
AplazadaCrítica (10)1.00%—Uvdesk CommunityAI25/4/202417/6/2026
Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.
AplazadaAlta (7.1)0.36%—Uvdesk Community SkeletonAI2/4/202417/6/2026
Improper Privilege Management in uvdesk/community-skeleton
ModificadaMedia (5.4)0.40%—Liveboxcloud Vdesk21/2/202417/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to the product) can store arbitrary HTML code in the reminder section…
ModificadaAlta (7.5)0.54%—Liveboxcloud Vdesk21/2/202417/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to…
ModificadaMedia (5.4)0.27%—Liveboxcloud Vdesk21/2/202417/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification…
ModificadaMedia (5.4)0.35%—Webkul Uvdesk23/10/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.
ModificadaCrítica (9.8)1.2%—Uvdesk Community-skeleton23/10/202317/6/2026
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.
ModificadaAlta (7.8)1.2%—Webkul Uvdesk1/8/202317/6/2026
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
ModificadaMedia (6.5)0.71%—Liveboxcloud Vdesk14/4/202317/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation…
ModificadaAlta (8.8)0.96%—Liveboxcloud Vdesk14/4/202317/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdeskintegration/saml/user/createorupdate endpoint, the /settings/guest-settings endpoint, the /settings/samlusers-settings endpoint, and the /settings/users-settings endpoint. A malicious user (already…
ModificadaMedia (6.5)0.72%—Liveboxcloud Vdesk14/4/202317/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/{N]/{C]/websocket endpoint. A malicious unauthenticated user can access cached files in the OnlyOffice backend of other users by guessing the file ID of a target file.
ModificadaCrítica (9.8)1.0%—Liveboxcloud Vdesk14/4/202317/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is not checked properly, and can be bypassed by passing any string…
ModificadaCrítica (9.8)1.0%—Liveboxcloud Vdesk14/4/202317/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding…
ModificadaMedia (6.5)0.44%—Liveboxcloud Vdesk14/4/202317/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user.
ModificadaMedia (6.1)0.69%—Uvdesk Community-skeleton4/4/202317/6/2026
Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket.
ModificadaAlta (8.8)1.6%—Uvdesk Community-skeleton4/4/202317/6/2026
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.
ModificadaMedia (4.8)0.40%—Uvdesk Community-skeleton6/3/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.