Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.34% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body. | |
| Aplazada | Media (6.5) | 0.37% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users. | |
| Aplazada | Alta (7.5) | 0.41% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users'… | |
| Aplazada | Media (4.3) | 0.25% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site. | |
| Aplazada | Media (6.5) | 0.37% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets. | |
| Analizada | Crítica (9.8) | 1.0% | — | Solarwinds WEB Help Desk | 30/7/2026 | 17/8/2026 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled. | |
| Aplazada | Media (5.3) | 0.31% | — | Jshelpdesk JS Help DeskAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions. | |
| Aplazada | Alta (7.7) | 0.47% | — | Jshelpdesk JS Help DeskAI | 25/6/2026 | 25/6/2026 | Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Jshelpdesk JS Help DeskAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Jshelpdesk JS Help DeskAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. | |
| Analizada | Alta (7.5) | 0.71% | — | Solarwinds WEB Help Desk | 2/6/2026 | 22/7/2026 | SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory. | |
| Aplazada | Alta (7.5) | 0.30% | — | Jshelpdesk JS Help DeskAI | 26/3/2026 | 17/6/2026 | The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being passed to `esc_sql()` without enclosing… | |
| Aplazada | Media (6.5) | 0.27% | — | Joomsky JS Help DeskAI | 25/3/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through <= 3.0.3. | |
| Aplazada | Alta (8.5) | 0.36% | — | Joomsky JS Help DeskAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.3. | |
| Aplazada | Alta (7.5) | 1.3% | — | Jshelpdesk JS Help DeskAI | 4/3/2026 | 17/6/2026 | The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied values and lack of… | |
| Aplazada | Alta (8.5) | 0.22% | — | Joomsky JS Help DeskAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.1. | |
| Analizada | Crítica (9.8) | 61% | — | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk. | |
| Modificada | Crítica (9.8) | 68% | — | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | |
| Modificada | Crítica (9.8) | 52% | — | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication. | |
| Analizada | Crítica (9.8) | 84% | ⚠ Explotación activa | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | |
| Analizada | Alta (7.5) | 0.59% | — | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions. | |
| Analizada | Crítica (9.8) | 74% | ⚠ Explotación activa | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality. | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa | Solarwinds WEB Help Desk | 23/9/2025 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of… | |
| Analizada | Crítica (9.8) | 39% | — | Solarwinds WEB Help Desk | 1/9/2025 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI… | |
| Analizada | Media (6.5) | 0.27% | — | Solarwinds WEB Help Desk | 29/7/2025 | 17/6/2026 | SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files. |