Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.92%—Kibokolabs Chained Quiz20/8/201917/6/2026
The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)1.6%—Quizandsurveymaster Quiz AND Survey Master5/3/201917/6/2026
The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.
ModificadaMedia (5.4)0.66%—Vms-studio Quizlord17/9/201817/6/2026
The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php.
ModificadaAlta (8.8)1.8%—Squiz Matrix30/11/201717/6/2026
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.
ModificadaMedia (6.1)0.60%—Squiz Matrix30/11/201717/6/2026
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins.
ModificadaAlta (7.5)2.2%—Squiz Matrix30/11/201717/6/2026
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.
ModificadaMedia (5)2.7%—Quiz Project Quiz1/9/201517/6/2026
The Quiz extension for MediaWiki allows remote attackers to cause a denial of service via regex metacharacters in a regular expression.
ModificadaBaja (3.5)0.95%—Quizzler Project Quizzler21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Quizzler module before 7-x.1.16 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.
ModificadaMedia (6.8)1.3%—Savsoft Technologies Savsoft Quiz13/1/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in index.php/user_data/insert_user in Savsoft Quiz allows remote attackers to hijack the authentication of administrators for requests that create an administrator account via a crafted request.
ModificadaMedia (4.3)2.0%—Mtouch Quiz Project Mtouch Quiz13/1/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in question.php in the mTouch Quiz before 3.0.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the quiz parameter to wp-admin/edit.php.
ModificadaAlta (7.5)2.3%—Mtouch Quiz Project Mtouch Quiz13/1/201517/6/2026
SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the quiz parameter to wp-admin/edit.php.
ModificadaMedia (5.4)0.27%—Aiadp Guess THE Pixel Character Quiz20/10/201417/6/2026
The Guess the Pixel Character Quiz (aka com.aiadp.pixelcQuiz) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Rgsmartapps Colormania - Color Quiz Game11/10/201417/6/2026
The ColorMania - Color Quiz Game (aka com.ColormaniaColoringGames) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Physics Chemistry Biology Quiz Project Physics Chemistry Biology Quiz11/10/201417/6/2026
The Physics Chemistry Biology Quiz (aka com.pdevsmcqs.pcbmcqseries) application 1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Bowenehs CIH Quiz Game29/9/201417/6/2026
The CIH Quiz game (aka com.bowenehs.cihquizgameapp) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Medquiz\ Medical Chat AND Mcqs Project25/9/201417/6/2026
The MedQuiz: Medical Chat and MCQs (aka com.pdevsmedd.med) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Superheroquiz Project Superheroquiz23/9/201417/6/2026
The superheroquiz (aka com.davidhey.superheroquiz) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5)1.4%—Quiz Module Project Quiz13/5/201416/6/2026
The default views in the Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote attackers to obtain sensitive quiz results via unspecified vectors.
ModificadaMedia (4.9)1.1%—Quiz Module Project Quiz13/5/201416/6/2026
The Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote authenticated users with the "view any quiz results" or "view results for own quiz" permission to delete arbitrary results via the delete option.
ModificadaMedia (4.3)1.1%—Kurt Gusbeth Myquizpoll1/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in the My quiz and poll (myquizpoll) extension before 2.0.6 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.2%—Kurt Gusbeth Myquizpoll1/7/201316/6/2026
SQL injection vulnerability in the My quiz and poll (myquizpoll) extension before 2.0.6 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.7%💥 ExploitTamlyncreative COM Bfquiztrial2/11/201116/6/2026
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php.
ModificadaMedia (4.3)1.7%💥 ExploitSquiz Mysource Matrix8/10/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.
ModificadaMedia (4.3)1.9%—Fubra Wp-survey-and-quiz-tool30/12/201016/6/2026
Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.
ModificadaAlta (7.5)0.97%💥 ExploitWire Plastic Design Wpquiz24/9/201016/6/2026
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) password (pw) parameters to (a) admin.php or (b) user.php.
Orbitaley — Vulnerabilidades