Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.43% | — | Intuit Quicken 2018 | 3/12/2018 | 17/6/2026 | An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password protection, allowing an attacker to access and modify the data without knowing the password. An… | |
| Modificada | Media (5.5) | 0.36% | — | Intel Quickassist Technology | 10/10/2018 | 17/6/2026 | Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an unprivileged user to potentially disclose information via local access. | |
| Modificada | Alta (8.8) | 0.71% | — | Quickappscms Quickapps CMS | 16/9/2018 | 17/6/2026 | An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI. | |
| Modificada | Alta (7.8) | 1.2% | 💥 PoC | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 25/7/2018 | 17/6/2026 | Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00… | |
| Modificada | Crítica (9.8) | 2.2% | — | Html Quickform Project Html QuickformCivicrm | 23/7/2018 | 17/6/2026 | PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, HTML_QuickForm_element's _prepareValue method. that can result in… | |
| Modificada | Crítica (9.8) | 1.5% | — | Quick Chat Project Quick Chat | 18/6/2018 | 17/6/2026 | A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress. | |
| Modificada | Alta (7.5) | 2.0% | — | Quickserver Project Quickserver | 7/6/2018 | 17/6/2026 | quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Media (5.3) | 1.7% | — | Easyquick Project Easyquick | 7/6/2018 | 17/6/2026 | easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Access is constrained, however, to supported file types. Requesting a file such as /etc/passwd returns a "not supported" error. | |
| Modificada | Media (6.1) | 0.81% | — | Multidots Woocommerce Quick Reports | 1/6/2018 | 17/6/2026 | The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order. | |
| Modificada | Alta (8.8) | 0.76% | — | Quickappscms Quickapps CMS | 28/3/2018 | 17/6/2026 | CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privileges. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Jquickcontact Project Jquickcontact | 17/2/2018 | 17/6/2026 | SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request. | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Quickad Project Quickad | 24/1/2018 | 17/6/2026 | SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI. | |
| Modificada | Media (5.4) | 0.63% | — | Quickappscms Quickapps CMS | 3/1/2018 | 17/6/2026 | QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account | |
| Modificada | Crítica (9.8) | 4.3% | — | Quickerbb Project Quickerbb | 17/11/2017 | 17/6/2026 | QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead to the complete takeover of the server hosting QuickerBB. | |
| Modificada | Media (6.5) | 1.1% | — | Libquicktime | 2/8/2017 | 17/6/2026 | In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Media (6.5) | 1.0% | — | Libquicktime | 2/8/2017 | 17/6/2026 | In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Alta (7.8) | 0.73% | — | Apple Quicktime | 7/7/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer of QuickTime for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Crítica (9.8) | 2.3% | — | Redhat Quickstart Cloud Installer | 13/6/2017 | 17/6/2026 | /var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system. | |
| Modificada | Media (6.5) | 3.8% | 💥 Exploit | Libquicktime | 12/6/2017 | 17/6/2026 | The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file. | |
| Modificada | Media (6.5) | 5.1% | 💥 Exploit | Libquicktime | 12/6/2017 | 17/6/2026 | The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file. | |
| Modificada | Media (6.5) | 4.0% | 💥 Exploit | Libquicktime | 12/6/2017 | 17/6/2026 | The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file. | |
| Modificada | Media (6.5) | 4.9% | 💥 Exploit | Libquicktime | 12/6/2017 | 17/6/2026 | The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file. | |
| Modificada | Media (6.5) | 3.8% | 💥 Exploit | Libquicktime | 12/6/2017 | 17/6/2026 | The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file. | |
| Modificada | Media (6.5) | 3.8% | 💥 Exploit | Libquicktime | 12/6/2017 | 17/6/2026 | The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file. | |
| Modificada | Media (6.5) | 6.5% | 💥 Exploit | Libquicktime | 12/6/2017 | 17/6/2026 | The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file. |