Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

791 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.66%—Pluginmirror WP Quick Frontend Editor7/6/202317/6/2026
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Setting Changs in versions up to, and including, 5.5. This is due to lacking both a security nonce and a capabilities check. This makes it possible for low-authenticated attackers to change plugin settings even when they do not have the capabilities to…
ModificadaMedia (6.1)0.74%—Webdevocean WP Quick Frontend Editor7/6/202317/6/2026
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on the 'save_content_front' function that uses print_r on the user-supplied $_REQUEST values . This makes it possible for…
ModificadaMedia (4.3)0.77%—Quick Page/post Redirect Project Quick Page/post Redirect7/6/202317/6/2026
The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for low-privileged attackers to interact with the plugin…
ModificadaCrítica (9.8)0.62%—Storecommander Quickaccounting25/5/202317/6/2026
In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
ModificadaCrítica (9.8)0.29%—Thingsforrestaurants Quick Restaurant Reservations22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.5.4 versions.
ModificadaMedia (6.5)0.47%—Storecommander Scquickaccounting16/5/202317/6/2026
Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table sush as name / surname / email
ModificadaAlta (7.5)0.73%—Quickjs Project Quickjs12/5/202317/6/2026
QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.
ModificadaAlta (8.8)0.61%—Intel Quickassist Technology Engine10/5/202317/6/2026
Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access.
ModificadaMedia (5.5)0.22%—Intel Quickassist Technology10/5/202317/6/2026
Improper buffer restriction in software for the Intel QAT Driver for Linux before version 1.7.l.4.12 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.18%—Intel Quickassist Technology10/5/202317/6/2026
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.17%—Intel Quickassist Technology10/5/202317/6/2026
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.17%—Intel Quickassist Technology10/5/202317/6/2026
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.15%—Intel Quickassist Technology10/5/202317/6/2026
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Intel Quickassist Technology10/5/202317/6/2026
Out-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.18%—Intel Quickassist Technology10/5/202317/6/2026
Out-of-bounds read in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (4.8)0.47%—Fullworksplugins Quick Paypal Payments2/5/202317/6/2026
The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.4)0.36%—Fullworksplugins Quick Paypal Payments25/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.
ModificadaMedia (4.8)0.37%—Fullworksplugins Quick Contact Form25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.
ModificadaMedia (6.1)0.41%—Fullworksplugins Quick Paypal Payments7/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.
ModificadaMedia (4.8)0.39%—Fullworksplugins Quick Paypal Payments7/4/202317/6/2026
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.
ModificadaMedia (5.4)0.39%—Fullworksplugins Quick Contact Form7/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.
ModificadaMedia (6.1)0.41%—Fullworksplugins Quick Event Manager6/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 versions.
ModificadaAlta (7.8)0.85%—Opclabs Quickopc29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XML files in…
ModificadaMedia (4.8)0.37%—Fullworksplugins Quick Event Manager28/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions.
ModificadaMedia (4.3)0.25%—Hasthemes Quickswish27/3/202317/6/2026
The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack