Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
844 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.56% | — | Fmemodules B2B Quick Order Form | 14/3/2024 | 17/6/2026 | SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods. | |
| Analizada | Alta (7.5) | 1.2% | — | Cloudflare Quiche | 12/3/2024 | 17/6/2026 | Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO… | |
| Analizada | Media (5.3) | 0.66% | — | Cloudflare Quiche | 12/3/2024 | 17/6/2026 | Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1… | |
| Modificada | Alta (8.8) | 0.21% | — | Developingtheweb Quicksand Post Filter Jquery | 21/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1. | |
| Modificada | Media (6.5) | 0.21% | — | Intel Quickassist Technology Driver | 14/2/2024 | 17/6/2026 | Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (6.5) | 0.25% | — | Pquic | 9/2/2024 | 17/6/2026 | In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is encrypted via the initial key computed. Network traffic sniffing is needed as part of exploitation. | |
| Modificada | Crítica (9.8) | 0.35% | — | Litespeedtech Lsquic | 9/2/2024 | 17/6/2026 | In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled. | |
| Modificada | Alta (7.5) | 0.77% | 💥 PoC | Eyuepcanyilmaz Root Quick Reboot | 5/2/2024 | 17/6/2026 | The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation. | |
| Modificada | Media (6.5) | 1.2% | — | Quic-go Project Quic-go | 10/1/2024 | 17/6/2026 | quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out of memory sending a large number of PATH_CHALLENGE frames. The receiver is supposed to respond to each PATH_CHALLENGE frame with a PATH_RESPONSE frame. The attacker can prevent the receiver… | |
| Modificada | Alta (7.8) | 0.24% | — | Innovadeluxe Quick Order | 28/12/2023 | 17/6/2026 | SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file. | |
| Modificada | Media (4.8) | 0.34% | — | Quick-plugins Loan Repayment Calculator AND Application Form | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aerin Loan Repayment Calculator and Application Form allows Stored XSS.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.3. | |
| Modificada | Media (6.1) | 0.47% | — | Crmperks Integration FOR Woocommerce AND Quickbooks | 19/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and QuickBooks.This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.2.3. | |
| Modificada | Baja (3.7) | 0.40% | — | Quicoto Thumbs Rating | 19/12/2023 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.0.0. | |
| Modificada | Media (6.1) | 0.40% | — | Joomboost Easy Quick Contact | 14/12/2023 | 17/6/2026 | A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla. | |
| Modificada | Media (6.1) | 0.40% | — | Plasma-web Quickform | 14/12/2023 | 17/6/2026 | A reflected XSS vulnerability was discovered in the Quickform component for Joomla. | |
| Modificada | Media (5.3) | 0.76% | — | Cloudflare Quiche | 12/12/2023 | 17/6/2026 | quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated… | |
| Modificada | Media (4.8) | 0.39% | — | Codez Quick Call Button | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codez Quick Call Button plugin <= 1.2.9 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Intel Quickassist Technology | 14/11/2023 | 17/6/2026 | Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel Quickassist Technology LibraryIntel Quickassist Technology | 14/11/2023 | 17/6/2026 | Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Quickassist Technology LibraryIntel Quickassist Technology | 14/11/2023 | 17/6/2026 | Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Quickassist Technology LibraryIntel Quickassist Technology Firmware | 14/11/2023 | 17/6/2026 | Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Baja (2.3) | 0.21% | — | Intel Quickassist Technology LibraryIntel Quickassist Technology Driver FirmwareIntel QAT Driver Firmware | 14/11/2023 | 17/6/2026 | Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.8) | 0.39% | — | Grandplugins WOO Quick View AND BUY NOW | 14/11/2023 | 17/6/2026 | Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in GrandPlugins Direct Checkout – Quick View – Buy Now For WooCommerce plugin <= 1.5.8 versions. | |
| Modificada | Media (5.5) | 0.19% | — | Samsung Quick Share | 7/11/2023 | 17/6/2026 | Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files. | |
| Modificada | Alta (7.5) | 0.77% | — | Quic-go Project Quic-go | 31/10/2023 | 17/6/2026 | quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could trigger a nil pointer dereference (leading to a panic) when the node attempted to drop the… |