Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
844 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.73% | — | Quickjs Project Quickjs | 12/5/2023 | 17/6/2026 | QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c. | |
| Modificada | Alta (8.8) | 0.61% | — | Intel Quickassist Technology Engine | 10/5/2023 | 17/6/2026 | Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Improper buffer restriction in software for the Intel QAT Driver for Linux before version 1.7.l.4.12 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.17% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Out-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Out-of-bounds read in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.8) | 0.47% | — | Fullworksplugins Quick Paypal Payments | 2/5/2023 | 17/6/2026 | The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.36% | — | Fullworksplugins Quick Paypal Payments | 25/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Fullworksplugins Quick Contact Form | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Fullworksplugins Quick Paypal Payments | 7/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Fullworksplugins Quick Paypal Payments | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Fullworksplugins Quick Contact Form | 7/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Fullworksplugins Quick Event Manager | 6/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 versions. | |
| Modificada | Alta (7.8) | 0.85% | — | Opclabs Quickopc | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XML files in… | |
| Modificada | Media (4.8) | 0.37% | — | Fullworksplugins Quick Event Manager | 28/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions. | |
| Modificada | Media (4.3) | 0.25% | — | Hasthemes Quickswish | 27/3/2023 | 17/6/2026 | The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Crítica (9.8) | 0.60% | — | Atm-consulting Dolibarr Module Quicksupplierprice | 20/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6. Affected by this issue is the function upatePrice of the file script/interface.php. The manipulation leads to sql injection. The attack may be launched remotely. Upgrading to version… | |
| Modificada | Baja (3.3) | 0.16% | — | Samsung Quick Share | 16/3/2023 | 17/6/2026 | The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission. | |
| Modificada | Media (6.1) | 0.32% | — | Quickentity Editor Project Quickentity Editor | 6/3/2023 | 17/6/2026 | quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file containing a script tag in any entity name.… | |
| Modificada | Media (5.4) | 0.23% | — | Fullworksplugins Quick Event Manager | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete all, edit, update). | |
| Modificada | Media (5.4) | 0.53% | — | Quick-plugins Loan Comparison | 21/2/2023 | 17/6/2026 | The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.3) | 0.18% | — | Intel Quickassist Technology | 16/2/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) QAT drivers for Windows before version 1.6 may allow an authenticated user to potentially enable escalation of privilege via local access. |