Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

844 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security4/5/201717/6/2026
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file.
ModificadaCrítica (9.8)2.3%—Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security4/5/201717/6/2026
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMHEADER_V1_PACKED. This vulnerability can be exploited to gain Remote…
ModificadaCrítica (9.8)2.0%—Apple Quicktime24/4/201716/6/2026
Buffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary code.
ModificadaAlta (7.5)5.5%💥 ExploitQuickheal Total Security20/4/201717/6/2026
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
ModificadaMedia (4.6)0.42%—Redhat Quickstart Cloud Installer14/4/201717/6/2026
The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.
ModificadaAlta (7.5)1.4%—Intel Quickassist Technology Engine7/3/201717/6/2026
The RSA-CRT implementation in the Intel QuickAssist Technology (QAT) Engine for OpenSSL versions prior to 0.5.19 may allow remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.
ModificadaMedia (6.2)1.0%—Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware5/2/201717/6/2026
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.
ModificadaAlta (7.5)1.8%—Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware5/2/201717/6/2026
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. The application failed to check the access control of the request which could result in an attacker being able to shutdown the system.
ModificadaCrítica (9.8)2.4%—Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware5/2/201717/6/2026
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands.
ModificadaAlta (7.8)7.2%💥 ExploitLibquicktime30/1/201717/6/2026
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted hdlr MP4 atom.
ModificadaCrítica (9.8)9.7%💥 PoCQuickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security2/1/201717/6/2026
Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security…
ModificadaAlta (8.4)0.39%—Redhat Quickstart Cloud Installer22/9/201617/6/2026
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack.
ModificadaAlta (8.4)0.39%—Redhat Quickstart Cloud Installer22/9/201617/6/2026
Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file.
ModificadaMedia (6.6)1.7%—Apple Quicktime9/1/201617/6/2026
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, and…
ModificadaMedia (6.6)1.8%—Apple Quicktime9/1/201617/6/2026
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted TXXX frame within an ID3 tag in MP3 data in a movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087,…
ModificadaMedia (6.6)1.4%—Apple Quicktime9/1/201617/6/2026
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7092, and…
ModificadaMedia (6.6)1.6%—Apple Quicktime9/1/201617/6/2026
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7091, CVE-2015-7092, and…
ModificadaMedia (6.6)1.6%—Apple Quicktime9/1/201617/6/2026
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and…
ModificadaMedia (6.6)1.7%—Apple Quicktime9/1/201617/6/2026
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and…
ModificadaMedia (6.6)1.6%—Apple Quicktime9/1/201617/6/2026
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and…
ModificadaMedia (6.6)1.3%—Apple Quicktime9/1/201617/6/2026
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and…
ModificadaMedia (6.6)1.3%—Apple Quicktime9/1/201617/6/2026
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and…
ModificadaBaja (3.5)0.77%—Quick Edit Project Quick Edit31/8/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Quick Edit module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) entity title, related to in-place editing, or a (2) node title.
ModificadaMedia (6.8)3.2%—Apple Quicktime25/8/201517/6/2026
Apple QuickTime before 7.7.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-5785.
ModificadaMedia (6.8)2.8%—Apple Quicktime25/8/201517/6/2026
Apple QuickTime before 7.7.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-5786.
Orbitaley — Vulnerabilidades