Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.7% | — | Quickbox | 24/1/2022 | 17/6/2026 | In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function without properly sanitizing any shell arguments, therefore remote code execution is possible. Additionally, as the media server is running as root by default attackers… | |
| Modificada | Alta (8.8) | 1.5% | — | Talariax Sendquick Alert Plus Server Admin | 14/11/2021 | 17/6/2026 | A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management. | |
| Analizada | Crítica (9.8) | 74% | ⚠ Explotación activa💥 Exploit | BQE Billquick WEB Suite | 22/10/2021 | 17/6/2026 | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to… | |
| Modificada | Alta (7.5) | 1.6% | — | Quickjs Project Quickjs | 13/7/2021 | 17/6/2026 | Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service. This issue is resolved in the 2020-07-05 release. | |
| Modificada | Alta (7.2) | 10% | 💥 Exploit | Opensolution Quick.cartOpensolution Quick.cms | 28/1/2021 | 17/6/2026 | OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab. | |
| Modificada | Media (6.7) | 0.36% | — | Quickheal Total Security | 30/11/2020 | 17/6/2026 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password. | |
| Modificada | Media (5.9) | 0.70% | — | Quickheal Total Security | 30/11/2020 | 17/6/2026 | Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text. | |
| Modificada | Media (4.4) | 0.32% | — | Quickheal Total Security | 30/11/2020 | 17/6/2026 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password. | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.30% | — | Intel Quickassist Technology | 12/11/2020 | 17/6/2026 | Insufficiently protected credentials in the Intel(R) QAT for Linux before version 1.7.l.4.10.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.2) | 1.7% | — | Quickbox | 1/6/2020 | 17/6/2026 | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information via a grep of a /root/*.db or /etc/shadow file. | |
| Modificada | Alta (8.8) | 2.0% | — | Quickbox | 1/6/2020 | 17/6/2026 | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which means that the www-data user can execute arbitrary OS commands via the mysql -e option. | |
| Modificada | Alta (8.8) | 17% | 💥 Exploit | Quickbox | 1/6/2020 | 17/6/2026 | QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter. | |
| Modificada | Alta (7.5) | 4.3% | — | Pablosoftwaresolutions Quick 'N Easy WEB Server | 28/2/2020 | 17/6/2026 | The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free. | |
| Modificada | Alta (7.8) | 1.5% | — | Quickheal Antivirus FOR ServerQuickheal Antivirus PROQuickheal Home SecurityQuickheal Internet Security+2 | 24/2/2020 | 17/6/2026 | The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, AntiVirus for Server, and Total Security for Android. | |
| Modificada | Alta (7.8) | 0.82% | — | Acer Quick Access | 17/12/2019 | 17/6/2026 | In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through V3.00.3008, a REGULAR user can load an arbitrary unsigned DLL into the signed service's process, which is running as NT AUTHORITY\SYSTEM. This is a DLL Hijacking vulnerability (including search order… | |
| Modificada | Media (4.8) | 0.53% | — | Quick Tabs Project Quick Tabs | 21/11/2019 | 24/9/2026 | Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Alta (8.8) | 0.65% | — | Jayj Quicktag Project Jayj Quicktag | 16/8/2019 | 17/6/2026 | The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF. | |
| Modificada | Crítica (9.8) | 1.8% | — | Techytalk Quick Chat | 18/7/2019 | 17/6/2026 | TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request. | |
| Modificada | Alta (8.8) | 1.4% | — | Foxitsoftware Quick PDF Library | 24/12/2018 | 17/6/2026 | In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref entries using the DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access. | |
| Modificada | Crítica (9.8) | 1.7% | — | Foxitsoftware Quick PDF Library | 24/12/2018 | 17/6/2026 | In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref table pointers or invalid xref table data using the LoadFromFile, LoadFromString, LoadFromStream, DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out… | |
| Modificada | Alta (7.8) | 54% | — | Foxitsoftware Quick PDF Library | 24/12/2018 | 17/6/2026 | In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow. | |
| Modificada | Media (5.5) | 0.28% | — | Intel Quickassist Technology FOR Linux | 14/12/2018 | 17/6/2026 | Improper memory handling in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.28% | — | Intel Quickassist Technology FOR Linux | 14/12/2018 | 17/6/2026 | Improper configuration of hardware access in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access. |