Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.66% | — | Pluginmirror WP Quick Frontend Editor | 7/6/2023 | 17/6/2026 | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Setting Changs in versions up to, and including, 5.5. This is due to lacking both a security nonce and a capabilities check. This makes it possible for low-authenticated attackers to change plugin settings even when they do not have the capabilities to… | |
| Modificada | Media (6.1) | 0.74% | — | Webdevocean WP Quick Frontend Editor | 7/6/2023 | 17/6/2026 | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on the 'save_content_front' function that uses print_r on the user-supplied $_REQUEST values . This makes it possible for… | |
| Modificada | Media (4.3) | 0.77% | — | Quick Page/post Redirect Project Quick Page/post Redirect | 7/6/2023 | 17/6/2026 | The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for low-privileged attackers to interact with the plugin… | |
| Modificada | Crítica (9.8) | 0.62% | — | Storecommander Quickaccounting | 25/5/2023 | 17/6/2026 | In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | |
| Modificada | Crítica (9.8) | 0.29% | — | Thingsforrestaurants Quick Restaurant Reservations | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.5.4 versions. | |
| Modificada | Media (6.5) | 0.47% | — | Storecommander Scquickaccounting | 16/5/2023 | 17/6/2026 | Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table sush as name / surname / email | |
| Modificada | Alta (7.5) | 0.73% | — | Quickjs Project Quickjs | 12/5/2023 | 17/6/2026 | QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c. | |
| Modificada | Alta (8.8) | 0.61% | — | Intel Quickassist Technology Engine | 10/5/2023 | 17/6/2026 | Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Improper buffer restriction in software for the Intel QAT Driver for Linux before version 1.7.l.4.12 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.17% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Out-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Out-of-bounds read in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.8) | 0.47% | — | Fullworksplugins Quick Paypal Payments | 2/5/2023 | 17/6/2026 | The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.36% | — | Fullworksplugins Quick Paypal Payments | 25/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Fullworksplugins Quick Contact Form | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Fullworksplugins Quick Paypal Payments | 7/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Fullworksplugins Quick Paypal Payments | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Fullworksplugins Quick Contact Form | 7/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Fullworksplugins Quick Event Manager | 6/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 versions. | |
| Modificada | Alta (7.8) | 0.85% | — | Opclabs Quickopc | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XML files in… | |
| Modificada | Media (4.8) | 0.37% | — | Fullworksplugins Quick Event Manager | 28/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions. | |
| Modificada | Media (4.3) | 0.25% | — | Hasthemes Quickswish | 27/3/2023 | 17/6/2026 | The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack |