Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

844 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.2%💥 PoCQuickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security25/7/201817/6/2026
Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00…
ModificadaCrítica (9.8)2.2%—Html Quickform Project Html QuickformCivicrm23/7/201817/6/2026
PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, HTML_QuickForm_element's _prepareValue method. that can result in…
ModificadaCrítica (9.8)1.5%—Quick Chat Project Quick Chat18/6/201817/6/2026
A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress.
ModificadaAlta (7.5)2.0%—Quickserver Project Quickserver7/6/201817/6/2026
quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaMedia (5.3)1.7%—Easyquick Project Easyquick7/6/201817/6/2026
easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Access is constrained, however, to supported file types. Requesting a file such as /etc/passwd returns a "not supported" error.
ModificadaMedia (6.1)0.81%—Multidots Woocommerce Quick Reports1/6/201817/6/2026
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
ModificadaAlta (8.8)0.76%—Quickappscms Quickapps CMS28/3/201817/6/2026
CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privileges.
ModificadaCrítica (9.8)2.7%💥 ExploitJquickcontact Project Jquickcontact17/2/201817/6/2026
SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.
ModificadaCrítica (9.8)19%💥 ExploitQuickad Project Quickad24/1/201817/6/2026
SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.
ModificadaMedia (5.4)0.63%—Quickappscms Quickapps CMS3/1/201817/6/2026
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account
ModificadaCrítica (9.8)4.3%—Quickerbb Project Quickerbb17/11/201717/6/2026
QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead to the complete takeover of the server hosting QuickerBB.
ModificadaMedia (6.5)1.1%—Libquicktime2/8/201717/6/2026
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.
ModificadaMedia (6.5)1.0%—Libquicktime2/8/201717/6/2026
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted file.
ModificadaAlta (7.8)0.73%—Apple Quicktime7/7/201717/6/2026
Untrusted search path vulnerability in Installer of QuickTime for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaCrítica (9.8)2.3%—Redhat Quickstart Cloud Installer13/6/201717/6/2026
/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.
ModificadaMedia (6.5)3.8%💥 ExploitLibquicktime12/6/201717/6/2026
The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file.
ModificadaMedia (6.5)5.1%💥 ExploitLibquicktime12/6/201717/6/2026
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.
ModificadaMedia (6.5)4.0%💥 ExploitLibquicktime12/6/201717/6/2026
The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.
ModificadaMedia (6.5)4.9%💥 ExploitLibquicktime12/6/201717/6/2026
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file.
ModificadaMedia (6.5)3.8%💥 ExploitLibquicktime12/6/201717/6/2026
The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
ModificadaMedia (6.5)3.8%💥 ExploitLibquicktime12/6/201717/6/2026
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
ModificadaMedia (6.5)6.5%💥 ExploitLibquicktime12/6/201717/6/2026
The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
ModificadaMedia (5.9)0.48%—Mypayquicker5/5/201717/6/2026
The PayQuicker app 1.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)0.93%—Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security4/5/201717/6/2026
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 have approximately 165 PE files in the default installation that do not use ASLR/DEP protection mechanisms that provide sufficient defense against directed attacks against the product.
ModificadaCrítica (9.8)1.2%—Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security4/5/201717/6/2026
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file.
Orbitaley — Vulnerabilidades