Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.92% | — | Kibokolabs Chained Quiz | 20/8/2019 | 17/6/2026 | The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 1.6% | — | Quizandsurveymaster Quiz AND Survey Master | 5/3/2019 | 17/6/2026 | The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS. | |
| Modificada | Media (5.4) | 0.66% | — | Vms-studio Quizlord | 17/9/2018 | 17/6/2026 | The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php. | |
| Modificada | Alta (8.8) | 1.8% | — | Squiz Matrix | 30/11/2017 | 17/6/2026 | An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag. | |
| Modificada | Media (6.1) | 0.60% | — | Squiz Matrix | 30/11/2017 | 17/6/2026 | An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins. | |
| Modificada | Alta (7.5) | 2.2% | — | Squiz Matrix | 30/11/2017 | 17/6/2026 | An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed. | |
| Modificada | Media (5) | 2.7% | — | Quiz Project Quiz | 1/9/2015 | 17/6/2026 | The Quiz extension for MediaWiki allows remote attackers to cause a denial of service via regex metacharacters in a regular expression. | |
| Modificada | Baja (3.5) | 0.95% | — | Quizzler Project Quizzler | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Quizzler module before 7-x.1.16 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title. | |
| Modificada | Media (6.8) | 1.3% | — | Savsoft Technologies Savsoft Quiz | 13/1/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in index.php/user_data/insert_user in Savsoft Quiz allows remote attackers to hijack the authentication of administrators for requests that create an administrator account via a crafted request. | |
| Modificada | Media (4.3) | 2.0% | — | Mtouch Quiz Project Mtouch Quiz | 13/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in question.php in the mTouch Quiz before 3.0.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the quiz parameter to wp-admin/edit.php. | |
| Modificada | Alta (7.5) | 2.3% | — | Mtouch Quiz Project Mtouch Quiz | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the quiz parameter to wp-admin/edit.php. | |
| Modificada | Media (5.4) | 0.27% | — | Aiadp Guess THE Pixel Character Quiz | 20/10/2014 | 17/6/2026 | The Guess the Pixel Character Quiz (aka com.aiadp.pixelcQuiz) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Rgsmartapps Colormania - Color Quiz Game | 11/10/2014 | 17/6/2026 | The ColorMania - Color Quiz Game (aka com.ColormaniaColoringGames) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Physics Chemistry Biology Quiz Project Physics Chemistry Biology Quiz | 11/10/2014 | 17/6/2026 | The Physics Chemistry Biology Quiz (aka com.pdevsmcqs.pcbmcqseries) application 1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Bowenehs CIH Quiz Game | 29/9/2014 | 17/6/2026 | The CIH Quiz game (aka com.bowenehs.cihquizgameapp) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Medquiz\ Medical Chat AND Mcqs Project | 25/9/2014 | 17/6/2026 | The MedQuiz: Medical Chat and MCQs (aka com.pdevsmedd.med) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Superheroquiz Project Superheroquiz | 23/9/2014 | 17/6/2026 | The superheroquiz (aka com.davidhey.superheroquiz) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.4% | — | Quiz Module Project Quiz | 13/5/2014 | 16/6/2026 | The default views in the Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote attackers to obtain sensitive quiz results via unspecified vectors. | |
| Modificada | Media (4.9) | 1.1% | — | Quiz Module Project Quiz | 13/5/2014 | 16/6/2026 | The Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote authenticated users with the "view any quiz results" or "view results for own quiz" permission to delete arbitrary results via the delete option. | |
| Modificada | Media (4.3) | 1.1% | — | Kurt Gusbeth Myquizpoll | 1/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the My quiz and poll (myquizpoll) extension before 2.0.6 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Kurt Gusbeth Myquizpoll | 1/7/2013 | 16/6/2026 | SQL injection vulnerability in the My quiz and poll (myquizpoll) extension before 2.0.6 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Tamlyncreative COM Bfquiztrial | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Squiz Mysource Matrix | 8/10/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Fubra Wp-survey-and-quiz-tool | 30/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Wire Plastic Design Wpquiz | 24/9/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) password (pw) parameters to (a) admin.php or (b) user.php. |