Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
844 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.23% | — | Intel Quickassist Technology | 16/2/2023 | 17/6/2026 | Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Elecom Camera AssistantElecom Quickfiledealer | 15/2/2023 | 17/6/2026 | Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (5.4) | 0.60% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | The Quick Restaurant Menu plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those actions intended for… | |
| Modificada | Media (4.3) | 0.36% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | The Quick Restaurant Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to update menu items, via forged request granted they can… | |
| Modificada | Media (4.8) | 0.54% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | The Quick Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Modificada | Media (4.3) | 0.65% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the fact that during menu item deletion/modification, the plugin does not verify that the post ID provided to the AJAX action is indeed a menu item. This makes it… | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Fullworksplugins Quick Event Manager | 20/1/2023 | 17/6/2026 | The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action. | |
| Modificada | Media (6.1) | 0.52% | — | Esri Arcgis Quickcapture | 15/11/2022 | 17/6/2026 | An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain. | |
| Modificada | Baja (3.5) | 0.20% | — | Samsung Quick Share | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in QuickShare prior to version 13.2.3.5 allows attackers to access sensitive information via implicit broadcast. | |
| Modificada | Media (4.8) | 0.61% | — | Thingsforrestaurants Quick Restaurant Reservations | 20/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1. | |
| Modificada | Alta (7.5) | 2.9% | 💥 PoC | Quic-go Project Quic-go | 6/7/2022 | 17/6/2026 | quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occurs because mtu_discoverer.go misparses the MTU Discovery service and consequently overflows the probe timer. NOTE: the vendor's position… | |
| Modificada | Media (5.4) | 0.30% | — | Quick Subscribe Project Quick Subscribe | 13/6/2022 | 17/6/2026 | The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them | |
| Modificada | Media (5.5) | 0.20% | — | Samsung Quick Share | 7/6/2022 | 17/6/2026 | Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share. | |
| Modificada | Alta (7.3) | 0.29% | — | Quickheal Total Security | 23/5/2022 | 17/6/2026 | A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not verifying the signature of the DLLs it tries… | |
| Modificada | Alta (7) | 0.16% | — | Quickheal Total Security | 23/5/2022 | 17/6/2026 | Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time between detecting a file as malicious and when the action of… | |
| Modificada | Crítica (9.8) | 3.3% | 💥 PoC | Litespeedtech Lsquic | 11/5/2022 | 17/6/2026 | liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY. | |
| Modificada | Crítica (9.8) | 1.8% | — | Oppo Quick APP | 1/4/2022 | 17/6/2026 | A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine | |
| Modificada | Alta (7.8) | 0.22% | — | Acer Quickaccess | 10/3/2022 | 17/6/2026 | Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority through a named pipe. In this case, the Named Pipe is also given Read and Write rights to the general user. In addition, the… | |
| Modificada | Alta (8.8) | 1.8% | — | Quicklert | 10/3/2022 | 17/6/2026 | An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions… | |
| Modificada | Media (6.5) | 1.5% | — | Quicklert | 10/3/2022 | 17/6/2026 | The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data within the database (up to and including the administrative accounts' login IDs and passwords) via the… | |
| Modificada | Media (6.1) | 0.72% | — | Quickbox | 7/2/2022 | 17/6/2026 | QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not properly sanitized. | |
| Modificada | Alta (8.8) | 3.7% | — | Quickbox | 24/1/2022 | 17/6/2026 | In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function without properly sanitizing any shell arguments, therefore remote code execution is possible. Additionally, as the media server is running as root by default attackers… | |
| Modificada | Alta (8.8) | 1.5% | — | Talariax Sendquick Alert Plus Server Admin | 14/11/2021 | 17/6/2026 | A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management. | |
| Analizada | Crítica (9.8) | 74% | ⚠ Explotación activa💥 Exploit | BQE Billquick WEB Suite | 22/10/2021 | 17/6/2026 | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to… | |
| Modificada | Alta (7.5) | 1.6% | — | Quickjs Project Quickjs | 13/7/2021 | 17/6/2026 | Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service. This issue is resolved in the 2020-07-05 release. |