Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

791 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.43%—Intuit Quicken 20183/12/201817/6/2026
An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password protection, allowing an attacker to access and modify the data without knowing the password. An…
ModificadaMedia (5.5)0.36%—Intel Quickassist Technology10/10/201817/6/2026
Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an unprivileged user to potentially disclose information via local access.
ModificadaAlta (8.8)0.71%—Quickappscms Quickapps CMS16/9/201817/6/2026
An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI.
ModificadaAlta (7.8)1.2%💥 PoCQuickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security25/7/201817/6/2026
Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00…
ModificadaCrítica (9.8)2.2%—Html Quickform Project Html QuickformCivicrm23/7/201817/6/2026
PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, HTML_QuickForm_element's _prepareValue method. that can result in…
ModificadaCrítica (9.8)1.5%—Quick Chat Project Quick Chat18/6/201817/6/2026
A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress.
ModificadaAlta (7.5)2.0%—Quickserver Project Quickserver7/6/201817/6/2026
quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaMedia (5.3)1.7%—Easyquick Project Easyquick7/6/201817/6/2026
easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Access is constrained, however, to supported file types. Requesting a file such as /etc/passwd returns a "not supported" error.
ModificadaMedia (6.1)0.81%—Multidots Woocommerce Quick Reports1/6/201817/6/2026
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
ModificadaAlta (8.8)0.76%—Quickappscms Quickapps CMS28/3/201817/6/2026
CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privileges.
ModificadaCrítica (9.8)2.7%💥 ExploitJquickcontact Project Jquickcontact17/2/201817/6/2026
SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.
ModificadaCrítica (9.8)19%💥 ExploitQuickad Project Quickad24/1/201817/6/2026
SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.
ModificadaMedia (5.4)0.63%—Quickappscms Quickapps CMS3/1/201817/6/2026
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account
ModificadaCrítica (9.8)4.3%—Quickerbb Project Quickerbb17/11/201717/6/2026
QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead to the complete takeover of the server hosting QuickerBB.
ModificadaMedia (6.5)1.1%—Libquicktime2/8/201717/6/2026
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.
ModificadaMedia (6.5)1.0%—Libquicktime2/8/201717/6/2026
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted file.
ModificadaAlta (7.8)0.73%—Apple Quicktime7/7/201717/6/2026
Untrusted search path vulnerability in Installer of QuickTime for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaCrítica (9.8)2.3%—Redhat Quickstart Cloud Installer13/6/201717/6/2026
/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.
ModificadaMedia (6.5)3.8%💥 ExploitLibquicktime12/6/201717/6/2026
The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file.
ModificadaMedia (6.5)5.1%💥 ExploitLibquicktime12/6/201717/6/2026
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.
ModificadaMedia (6.5)4.0%💥 ExploitLibquicktime12/6/201717/6/2026
The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.
ModificadaMedia (6.5)4.9%💥 ExploitLibquicktime12/6/201717/6/2026
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file.
ModificadaMedia (6.5)3.8%💥 ExploitLibquicktime12/6/201717/6/2026
The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
ModificadaMedia (6.5)3.8%💥 ExploitLibquicktime12/6/201717/6/2026
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
ModificadaMedia (6.5)6.5%💥 ExploitLibquicktime12/6/201717/6/2026
The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
Orbitaley — Vulnerabilidades