Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

844 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.73%—Quickjs Project Quickjs12/5/202317/6/2026
QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.
ModificadaAlta (8.8)0.61%—Intel Quickassist Technology Engine10/5/202317/6/2026
Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access.
ModificadaMedia (5.5)0.22%—Intel Quickassist Technology10/5/202317/6/2026
Improper buffer restriction in software for the Intel QAT Driver for Linux before version 1.7.l.4.12 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.18%—Intel Quickassist Technology10/5/202317/6/2026
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.17%—Intel Quickassist Technology10/5/202317/6/2026
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.17%—Intel Quickassist Technology10/5/202317/6/2026
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.15%—Intel Quickassist Technology10/5/202317/6/2026
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Intel Quickassist Technology10/5/202317/6/2026
Out-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.18%—Intel Quickassist Technology10/5/202317/6/2026
Out-of-bounds read in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (4.8)0.47%—Fullworksplugins Quick Paypal Payments2/5/202317/6/2026
The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.4)0.36%—Fullworksplugins Quick Paypal Payments25/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.
ModificadaMedia (4.8)0.37%—Fullworksplugins Quick Contact Form25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.
ModificadaMedia (6.1)0.41%—Fullworksplugins Quick Paypal Payments7/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.
ModificadaMedia (4.8)0.39%—Fullworksplugins Quick Paypal Payments7/4/202317/6/2026
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.
ModificadaMedia (5.4)0.39%—Fullworksplugins Quick Contact Form7/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.
ModificadaMedia (6.1)0.41%—Fullworksplugins Quick Event Manager6/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 versions.
ModificadaAlta (7.8)0.85%—Opclabs Quickopc29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XML files in…
ModificadaMedia (4.8)0.37%—Fullworksplugins Quick Event Manager28/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions.
ModificadaMedia (4.3)0.25%—Hasthemes Quickswish27/3/202317/6/2026
The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaCrítica (9.8)0.60%—Atm-consulting Dolibarr Module Quicksupplierprice20/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6. Affected by this issue is the function upatePrice of the file script/interface.php. The manipulation leads to sql injection. The attack may be launched remotely. Upgrading to version…
ModificadaBaja (3.3)0.16%—Samsung Quick Share16/3/202317/6/2026
The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
ModificadaMedia (6.1)0.32%—Quickentity Editor Project Quickentity Editor6/3/202317/6/2026
quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file containing a script tag in any entity name.…
ModificadaMedia (5.4)0.23%—Fullworksplugins Quick Event Manager1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete all, edit, update).
ModificadaMedia (5.4)0.53%—Quick-plugins Loan Comparison21/2/202317/6/2026
The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7.3)0.18%—Intel Quickassist Technology16/2/202317/6/2026
Uncontrolled search path in some Intel(R) QAT drivers for Windows before version 1.6 may allow an authenticated user to potentially enable escalation of privilege via local access.
Orbitaley — Vulnerabilidades