Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.60% | — | Atm-consulting Dolibarr Module Quicksupplierprice | 20/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6. Affected by this issue is the function upatePrice of the file script/interface.php. The manipulation leads to sql injection. The attack may be launched remotely. Upgrading to version… | |
| Modificada | Baja (3.3) | 0.16% | — | Samsung Quick Share | 16/3/2023 | 17/6/2026 | The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission. | |
| Modificada | Media (6.1) | 0.32% | — | Quickentity Editor Project Quickentity Editor | 6/3/2023 | 17/6/2026 | quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file containing a script tag in any entity name.… | |
| Modificada | Media (5.4) | 0.23% | — | Fullworksplugins Quick Event Manager | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete all, edit, update). | |
| Modificada | Media (5.4) | 0.53% | — | Quick-plugins Loan Comparison | 21/2/2023 | 17/6/2026 | The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.3) | 0.18% | — | Intel Quickassist Technology | 16/2/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) QAT drivers for Windows before version 1.6 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.23% | — | Intel Quickassist Technology | 16/2/2023 | 17/6/2026 | Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Elecom Camera AssistantElecom Quickfiledealer | 15/2/2023 | 17/6/2026 | Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (5.4) | 0.60% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | The Quick Restaurant Menu plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those actions intended for… | |
| Modificada | Media (4.3) | 0.36% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | The Quick Restaurant Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to update menu items, via forged request granted they can… | |
| Modificada | Media (4.8) | 0.54% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | The Quick Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Modificada | Media (4.3) | 0.65% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the fact that during menu item deletion/modification, the plugin does not verify that the post ID provided to the AJAX action is indeed a menu item. This makes it… | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Fullworksplugins Quick Event Manager | 20/1/2023 | 17/6/2026 | The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action. | |
| Modificada | Media (6.1) | 0.52% | — | Esri Arcgis Quickcapture | 15/11/2022 | 17/6/2026 | An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain. | |
| Modificada | Baja (3.5) | 0.20% | — | Samsung Quick Share | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in QuickShare prior to version 13.2.3.5 allows attackers to access sensitive information via implicit broadcast. | |
| Modificada | Media (4.8) | 0.61% | — | Thingsforrestaurants Quick Restaurant Reservations | 20/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1. | |
| Modificada | Media (5.4) | 0.30% | — | Quick Subscribe Project Quick Subscribe | 13/6/2022 | 17/6/2026 | The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them | |
| Modificada | Media (5.5) | 0.20% | — | Samsung Quick Share | 7/6/2022 | 17/6/2026 | Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share. | |
| Modificada | Alta (7.3) | 0.29% | — | Quickheal Total Security | 23/5/2022 | 17/6/2026 | A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not verifying the signature of the DLLs it tries… | |
| Modificada | Alta (7) | 0.16% | — | Quickheal Total Security | 23/5/2022 | 17/6/2026 | Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time between detecting a file as malicious and when the action of… | |
| Modificada | Crítica (9.8) | 1.8% | — | Oppo Quick APP | 1/4/2022 | 17/6/2026 | A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine | |
| Modificada | Alta (7.8) | 0.22% | — | Acer Quickaccess | 10/3/2022 | 17/6/2026 | Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority through a named pipe. In this case, the Named Pipe is also given Read and Write rights to the general user. In addition, the… | |
| Modificada | Alta (8.8) | 1.8% | — | Quicklert | 10/3/2022 | 17/6/2026 | An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions… | |
| Modificada | Media (6.5) | 1.5% | — | Quicklert | 10/3/2022 | 17/6/2026 | The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data within the database (up to and including the administrative accounts' login IDs and passwords) via the… | |
| Modificada | Media (6.1) | 0.72% | — | Quickbox | 7/2/2022 | 17/6/2026 | QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not properly sanitized. |