Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

844 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.56%—Fmemodules B2B Quick Order Form14/3/202417/6/2026
SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods.
AnalizadaAlta (7.5)1.2%—Cloudflare Quiche12/3/202417/6/2026
Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO…
AnalizadaMedia (5.3)0.66%—Cloudflare Quiche12/3/202417/6/2026
Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1…
ModificadaAlta (8.8)0.21%—Developingtheweb Quicksand Post Filter Jquery21/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1.
ModificadaMedia (6.5)0.21%—Intel Quickassist Technology Driver14/2/202417/6/2026
Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (6.5)0.25%—Pquic9/2/202417/6/2026
In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is encrypted via the initial key computed. Network traffic sniffing is needed as part of exploitation.
ModificadaCrítica (9.8)0.35%—Litespeedtech Lsquic9/2/202417/6/2026
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
ModificadaAlta (7.5)0.77%💥 PoCEyuepcanyilmaz Root Quick Reboot5/2/202417/6/2026
The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation.
ModificadaMedia (6.5)1.2%—Quic-go Project Quic-go10/1/202417/6/2026
quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out of memory sending a large number of PATH_CHALLENGE frames. The receiver is supposed to respond to each PATH_CHALLENGE frame with a PATH_RESPONSE frame. The attacker can prevent the receiver…
ModificadaAlta (7.8)0.24%—Innovadeluxe Quick Order28/12/202317/6/2026
SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file.
ModificadaMedia (4.8)0.34%—Quick-plugins Loan Repayment Calculator AND Application Form21/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aerin Loan Repayment Calculator and Application Form allows Stored XSS.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.3.
ModificadaMedia (6.1)0.47%—Crmperks Integration FOR Woocommerce AND Quickbooks19/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and QuickBooks.This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.2.3.
ModificadaBaja (3.7)0.40%—Quicoto Thumbs Rating19/12/202317/6/2026
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.0.0.
ModificadaMedia (6.1)0.40%—Joomboost Easy Quick Contact14/12/202317/6/2026
A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.
ModificadaMedia (6.1)0.40%—Plasma-web Quickform14/12/202317/6/2026
A reflected XSS vulnerability was discovered in the Quickform component for Joomla.
ModificadaMedia (5.3)0.76%—Cloudflare Quiche12/12/202317/6/2026
quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated…
ModificadaMedia (4.8)0.39%—Codez Quick Call Button22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codez Quick Call Button plugin <= 1.2.9 versions.
ModificadaAlta (8.8)0.31%—Intel Quickassist Technology14/11/202317/6/2026
Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access.
ModificadaAlta (7.8)0.21%—Intel Quickassist Technology LibraryIntel Quickassist Technology14/11/202317/6/2026
Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Intel Quickassist Technology LibraryIntel Quickassist Technology14/11/202317/6/2026
Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.20%—Intel Quickassist Technology LibraryIntel Quickassist Technology Firmware14/11/202317/6/2026
Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaBaja (2.3)0.21%—Intel Quickassist Technology LibraryIntel Quickassist Technology Driver FirmwareIntel QAT Driver Firmware14/11/202317/6/2026
Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (4.8)0.39%—Grandplugins WOO Quick View AND BUY NOW14/11/202317/6/2026
Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in GrandPlugins Direct Checkout – Quick View – Buy Now For WooCommerce plugin <= 1.5.8 versions.
ModificadaMedia (5.5)0.19%—Samsung Quick Share7/11/202317/6/2026
Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.
ModificadaAlta (7.5)0.77%—Quic-go Project Quic-go31/10/202317/6/2026
quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could trigger a nil pointer dereference (leading to a panic) when the node attempted to drop the…