Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
844 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.7) | 0.38% | — | QuickcalAI | 23/7/2026 | 23/7/2026 | Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. | |
| Analizada | Crítica (9) | 0.57% | — | Delskayn RquickjsSurrealdb | 18/7/2026 | 13/8/2026 | SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges. | |
| Analizada | Alta (7.5) | 0.49% | — | H2O Quicly | 16/7/2026 | 21/7/2026 | Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack through connection state corruption. In QUIC Invariants, the maximum length of a Connection ID is 255 bytes, while QUIC version 1 further… | |
| Analizada | Alta (7.5) | 0.49% | — | H2O Quicly | 16/7/2026 | 6/8/2026 | Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure is raised when the total number of valid handshake messages received over a CRYPTO stream of a single packet number space exceeds 32KB, causing a Denial of Service. This… | |
| Analizada | Media (5.3) | 0.21% | — | H2O Quicly | 16/7/2026 | 6/8/2026 | Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless reset injection through lack of packet entry validation. The QUIC protocol is designed to withstand packet injection attacks, once the handshake is complete.… | |
| Analizada | Alta (7.5) | 0.49% | — | H2O Quicly | 16/7/2026 | 6/8/2026 | Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer could send a STREAM frame carrying just one byte at the largest offset being permitted to obtain additional flow control credit, which under certain circumstances could… | |
| Pendiente de análisis | Alta (7.5) | 0.44% | — | Cloudflare QuicheAI | 14/7/2026 | 14/7/2026 | Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connection migration features described in Section 9 of RFC 9000, which allows a single QUIC connection to survive changes in the… | |
| Analizada | Alta (7.5) | 0.53% | — | Cloudflare Quiche | 14/7/2026 | 6/8/2026 | Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple frame types to support HTTP message exchanges and connection management. Each frame has a length and a payload whose length depends… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Dbix QuickormAISQL AbstractAI | 30/6/2026 | 30/6/2026 | DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its constructor but never quote_char, so SQL::Abstract emits identifiers verbatim. Caller-supplied identifiers (order_by, where-clause column keys,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Quick Interest SliderAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions. | |
| Pendiente de análisis | Media (5.6) | 0.25% | — | Cloudflare QuicheAI | 19/6/2026 | 22/6/2026 | Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions would return a pointer to a “ConnectionId” to the applications via function arguments, but the owned “ConnectionId” would be… | |
| Aplazada | Alta (7.5) | 0.24% | — | Quick CMSAI | 15/6/2026 | 24/7/2026 | Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization is performed without proper validation or class restrictions, crafted payloads… | |
| Pendiente de análisis | Media (6.9) | 0.29% | — | Amazon S2n-quicAI | 10/6/2026 | 17/6/2026 | Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets. To remediate this issue, users should upgrade to v1.8.2. | |
| Aplazada | Media (4.4) | 0.32% | — | Quick PlaygroundAI | 6/6/2026 | 23/7/2026 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` function passing the user-supplied `filename` POST parameter directly to `file_get_contents()` without any validation, sanitization, or path restriction. This makes… | |
| Analizada | Alta (7.5) | 0.49% | — | Quic-go Project Quic-go | 4/6/2026 | 22/7/2026 | quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique field names and/or large… | |
| Aplazada | Baja (2.3) | 0.27% | — | QuickcmsAI | 29/5/2026 | 21/7/2026 | QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a Man‑in‑the‑Middle (MITM) attack by impersonating the opensolution.org server and serving arbitrary HTML or JavaScript at the plugin list endpoint. When a user accesses the… | |
| Aplazada | Media (4.8) | 0.21% | — | QuickcmsAI | 29/5/2026 | 21/7/2026 | QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in a patch to version 6.8 published on… | |
| Aplazada | Crítica (9.9) | 0.55% | — | Ludwig YOU QuickwebpAI | 27/5/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly:… | |
| Aplazada | Media (5.1) | 0.18% | — | Opensolution Quick.cmsAI | 16/5/2026 | 17/6/2026 | Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arbitrary JavaScript… | |
| Aplazada | Alta (7.5) | 1.2% | — | Quick PlaygroundAI | 15/5/2026 | 17/6/2026 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the theme root directory path without sanitizing directory… | |
| Analizada | Alta (8.5) | 0.11% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Alta (8.5) | 0.11% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Media (6.8) | 0.10% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Analizada | Media (6.9) | 0.10% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Analizada | Media (6.8) | 0.10% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via… |