Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 0.76% | — | Meta Tags Quick Project Meta Tags Quick | 10/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the path-based meta tag editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows remote authenticated users with the "Edit path based meta tags" permission to inject arbitrary web script or HTML via vectors related to deleting a Path-based Metatag. | |
| Modificada | Media (5.4) | 0.27% | — | Quickmobile Ncci's Annual Issues Symposium | 19/10/2014 | 17/6/2026 | The NCCI's Annual Issues Symposium (aka com.quickmobile.ais14) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 2.0% | — | Qpw.famvanakkeren Quick Post Widget | 3/9/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Title, (2) Content, or (3) New category field to wordpress/ or (4) query string to wordpress/. | |
| Modificada | Alta (9.3) | 3.6% | — | Apple Quicktime | 26/7/2014 | 17/6/2026 | Apple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed version number and flags in an mvhd atom. | |
| Modificada | Media (5) | 1.5% | — | Quick Tabs Module Project Quicktabs | 19/5/2014 | 16/6/2026 | The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not properly check block permissions, which allows remote attackers to obtain sensitive information by reading a Quick Tab. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Opensolution Quick.cartOpensolution Quick CMS | 24/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin.php. NOTE: this might be a duplicate of CVE-2008-4140. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Quickfile | 21/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM QuickFile 1.0.0.0 before iFix 4 and 1.1.0.1 before iFix 3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Alta (9.3) | 4.1% | — | Apple Quicktime | 27/2/2014 | 17/6/2026 | Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted clef atom in a movie file. | |
| Modificada | Alta (9.3) | 3.6% | — | Apple Quicktime | 27/2/2014 | 17/6/2026 | Apple QuickTime before 7.7.5 does not properly perform a byte-swapping operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted ttfo element in a movie file. | |
| Modificada | Alta (9.3) | 4.1% | — | Apple Quicktime | 27/2/2014 | 17/6/2026 | Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PSD image. | |
| Modificada | Alta (9.3) | 4.1% | — | Apple Quicktime | 27/2/2014 | 17/6/2026 | Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ldat atom in a movie file. | |
| Modificada | Alta (9.3) | 3.5% | — | Apple Quicktime | 27/2/2014 | 17/6/2026 | Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted dref atom in a movie file. | |
| Modificada | Alta (9.3) | 4.1% | — | Apple Quicktime | 27/2/2014 | 17/6/2026 | Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ftab atom in a movie file. | |
| Modificada | Alta (9.3) | 3.6% | — | Apple Quicktime | 27/2/2014 | 17/6/2026 | Integer signedness error in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted stsz atom in a movie file. | |
| Modificada | Alta (9.3) | 4.1% | — | Apple Quicktime | 27/2/2014 | 17/6/2026 | Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding. | |
| Modificada | Alta (9.3) | 3.6% | — | Apple Quicktime | 27/2/2014 | 17/6/2026 | Apple QuickTime before 7.7.5 does not initialize an unspecified pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted track list in a movie file. | |
| Modificada | Alta (7.5) | 4.0% | — | IBM Lotus Quickr FOR Domino | 29/1/2014 | 17/6/2026 | Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitrary code via a crafted HTML document, a different vulnerability than CVE-2013-6748. | |
| Modificada | Alta (7.5) | 3.1% | — | IBM Lotus Quickr FOR Domino | 29/1/2014 | 17/6/2026 | Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitrary code via a crafted HTML document, a different vulnerability than CVE-2013-6749. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Cynthia Fridsma Horizon Quick Content Management System | 9/1/2014 | 17/6/2026 | SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Media (5) | 1.9% | — | Horizon Quick Content Management System Project Horizon Quick Content Management System | 9/1/2014 | 17/6/2026 | Directory traversal vulnerability in lib/functions/d-load.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter. | |
| Modificada | Alta (9.3) | 4.7% | — | Apple Quicktime | 27/12/2013 | 16/6/2026 | Untrusted search path vulnerability in the Picture Viewer in Apple QuickTime before 7.6.8 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) CoreVideo.dll, (2) CoreGraphics.dll, or (3) CoreAudioToolbox.dll that is located in the same… | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Etoshop Dynamic BIZ Website Builder Quickweb | 21/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (3) Password to login.asp. | |
| Modificada | Alta (7.2) | 1.3% | 💥 Exploit | Quickheal Antivirus PRO | 20/12/2013 | 17/6/2026 | Stack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary code or cause a denial of service (process crash) via a long *.text value in a PE file. | |
| Modificada | Media (6.8) | 2.8% | — | Apple QuicktimeApple MAC OS X | 16/9/2013 | 16/6/2026 | QuickTime in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted idsc atom in a QuickTime movie file. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Telepresence TC SoftwareCisco IP Video Phone E20Cisco Telepresence Codec C40Cisco Telepresence Codec C60+10 | 21/6/2013 | 16/6/2026 | Cisco TelePresence TC Software before 5.1.7 and TE Software before 4.1.3 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCue01743. |