Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

844 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Privateoctopus Picoquic8/2/202117/6/2026
picoquic (before 3rd of July 2020) allows attackers to cause a denial of service (infinite loop) via a crafted QUIC frame, related to the picoquic_decode_frames and picoquic_decode_stream_frame functions and epoch==3.
ModificadaAlta (7.2)10%💥 ExploitOpensolution Quick.cartOpensolution Quick.cms28/1/202117/6/2026
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
ModificadaMedia (6.7)0.36%—Quickheal Total Security30/11/202017/6/2026
Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password.
ModificadaMedia (5.9)0.70%—Quickheal Total Security30/11/202017/6/2026
Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.
ModificadaMedia (4.4)0.32%—Quickheal Total Security30/11/202017/6/2026
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.
ModificadaAlta (7.8)0.34%—Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+2924/11/202017/6/2026
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)0.30%—Intel Quickassist Technology12/11/202017/6/2026
Insufficiently protected credentials in the Intel(R) QAT for Linux before version 1.7.l.4.10.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.2)1.7%—Quickbox1/6/202017/6/2026
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information via a grep of a /root/*.db or /etc/shadow file.
ModificadaAlta (8.8)2.0%—Quickbox1/6/202017/6/2026
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which means that the www-data user can execute arbitrary OS commands via the mysql -e option.
ModificadaAlta (8.8)17%💥 ExploitQuickbox1/6/202017/6/2026
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
ModificadaAlta (7.5)4.3%—Pablosoftwaresolutions Quick 'N Easy WEB Server28/2/202017/6/2026
The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.
ModificadaAlta (7.8)1.5%—Quickheal Antivirus FOR ServerQuickheal Antivirus PROQuickheal Home SecurityQuickheal Internet Security+224/2/202017/6/2026
The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, AntiVirus for Server, and Total Security for Android.
ModificadaAlta (7.8)0.82%—Acer Quick Access17/12/201917/6/2026
In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through V3.00.3008, a REGULAR user can load an arbitrary unsigned DLL into the signed service's process, which is running as NT AUTHORITY\SYSTEM. This is a DLL Hijacking vulnerability (including search order…
ModificadaMedia (4.8)0.53%—Quick Tabs Project Quick Tabs21/11/201924/9/2026
Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaAlta (8.8)0.65%—Jayj Quicktag Project Jayj Quicktag16/8/201917/6/2026
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
ModificadaCrítica (9.8)1.8%—Techytalk Quick Chat18/7/201917/6/2026
TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.
ModificadaAlta (8.8)1.4%—Foxitsoftware Quick PDF Library24/12/201817/6/2026
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref entries using the DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.
ModificadaCrítica (9.8)1.7%—Foxitsoftware Quick PDF Library24/12/201817/6/2026
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref table pointers or invalid xref table data using the LoadFromFile, LoadFromString, LoadFromStream, DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out…
ModificadaAlta (7.8)54%—Foxitsoftware Quick PDF Library24/12/201817/6/2026
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow.
ModificadaMedia (5.5)0.28%—Intel Quickassist Technology FOR Linux14/12/201817/6/2026
Improper memory handling in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaMedia (5.5)0.28%—Intel Quickassist Technology FOR Linux14/12/201817/6/2026
Improper configuration of hardware access in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaAlta (7.1)0.43%—Intuit Quicken 20183/12/201817/6/2026
An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password protection, allowing an attacker to access and modify the data without knowing the password. An…
ModificadaMedia (5.5)0.36%—Intel Quickassist Technology10/10/201817/6/2026
Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an unprivileged user to potentially disclose information via local access.
ModificadaAlta (8.8)0.71%—Quickappscms Quickapps CMS16/9/201817/6/2026
An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI.