Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

844 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.48%💥 PoCOpensolution Quick CMS20/10/202317/6/2026
Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Backend - Dashboard parameter in the Languages Menu component.
ModificadaAlta (8.6)0.36%💥 PoCOpensolution Quick CMS19/10/202317/6/2026
Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Content - Name parameter in the Pages Menu component.
ModificadaMedia (5.4)0.64%💥 PoCOpensolution Quick CMS19/10/202317/6/2026
Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the SEO - Meta description parameter in the Pages Menu component.
ModificadaMedia (5.4)0.49%💥 PoCOpensolution Quick CMS19/10/202317/6/2026
Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Languages Menu component.
ModificadaMedia (5.4)0.69%💥 PoCOpensolution Quick CMS5/10/202317/6/2026
Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Files - Description parameter in the Pages Menu component.
ModificadaAlta (7.4)0.35%—Selinc Sel-5030 Acselerator Quickset31/8/202317/6/2026
An Incomplete Filtering of Special Elements vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated 20230615 for more…
ModificadaMedia (6.5)0.34%—Selinc Sel-5030 Acselerator Quickset31/8/202317/6/2026
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix…
ModificadaMedia (6.5)0.35%—Selinc Sel-5030 Acselerator Quickset31/8/202317/6/2026
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated…
ModificadaMedia (5.7)0.43%—Selinc Sel-5030 Acselerator Quickset31/8/202317/6/2026
An Improper Handling of Unicode Encoding vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated 20230615 for more…
ModificadaMedia (6.5)0.39%—Selinc Sel-5030 Acselerator Quickset31/8/202317/6/2026
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated…
ModificadaMedia (4.8)0.37%—Anadnet Quick Page/post Redirect Plugin8/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anadnet Quick Page/Post Redirect Plugin plugin <= 5.2.3 versions.
ModificadaCrítica (9.8)0.50%—Bylancer Quickorder16/7/202317/6/2026
A vulnerability, which was classified as critical, has been found in Bylancer QuickOrder 6.3.7. Affected by this issue is some unknown functionality of the file /blog of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection. The attack may be launched remotely. The identifier…
ModificadaCrítica (9.8)0.50%—Bylancer Quickqr16/7/202317/6/2026
A vulnerability classified as critical was found in Bylancer QuickQR 6.3.7. Affected by this vulnerability is an unknown functionality of the file /blog of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection. The attack can be launched remotely. The associated identifier of…
ModificadaCrítica (9.8)0.50%—Bylancer Quickjob16/7/202317/6/2026
A vulnerability classified as critical has been found in Bylancer QuickJob 6.1. Affected is an unknown function of the component GET Parameter Handler. The manipulation of the argument keywords/gender leads to sql injection. It is possible to launch the attack remotely. VDB-234234 is the identifier assigned to this…
ModificadaCrítica (9.8)0.50%—Bylancer Quickvcard16/7/202317/6/2026
A vulnerability was found in Bylancer QuickVCard 2.1. It has been rated as critical. This issue affects some unknown processing of the file /blog of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection. The attack may be initiated remotely. The identifier VDB-234233 was…
ModificadaCrítica (9.8)0.50%—Bylancer Quickai Openai16/7/202317/6/2026
A vulnerability was found in Bylancer QuickAI OpenAI 3.8.1. It has been declared as critical. This vulnerability affects unknown code of the file /blog of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection. The attack can be initiated remotely. The identifier of this…
ModificadaMedia (4.8)0.37%—Wpovernight Download Quick/bulk Order Form FOR Woocommerce22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Overnight Quick/Bulk Order Form for WooCommerce plugin <= 3.5.7 versions.
ModificadaMedia (4.3)0.79%—Webdevocean WP Quick Frontend Editor7/6/202317/6/2026
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as subscribers, to edit/create any page or…
ModificadaMedia (5.4)0.49%—Webdevocean WP Quick Frontend Editor7/6/202317/6/2026
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with minimal permissions like subscribers, to inject arbitrary web scripts…
ModificadaMedia (4.3)0.66%—Pluginmirror WP Quick Frontend Editor7/6/202317/6/2026
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Setting Changs in versions up to, and including, 5.5. This is due to lacking both a security nonce and a capabilities check. This makes it possible for low-authenticated attackers to change plugin settings even when they do not have the capabilities to…
ModificadaMedia (6.1)0.74%—Webdevocean WP Quick Frontend Editor7/6/202317/6/2026
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on the 'save_content_front' function that uses print_r on the user-supplied $_REQUEST values . This makes it possible for…
ModificadaMedia (4.3)0.77%—Quick Page/post Redirect Project Quick Page/post Redirect7/6/202317/6/2026
The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for low-privileged attackers to interact with the plugin…
ModificadaCrítica (9.8)0.62%—Storecommander Quickaccounting25/5/202317/6/2026
In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
ModificadaCrítica (9.8)0.29%—Thingsforrestaurants Quick Restaurant Reservations22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.5.4 versions.
ModificadaMedia (6.5)0.47%—Storecommander Scquickaccounting16/5/202317/6/2026
Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table sush as name / surname / email
Orbitaley — Vulnerabilidades