Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.32% | — | Quick PlaygroundAI | 6/6/2026 | 23/7/2026 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` function passing the user-supplied `filename` POST parameter directly to `file_get_contents()` without any validation, sanitization, or path restriction. This makes… | |
| Aplazada | Baja (2.3) | 0.27% | — | QuickcmsAI | 29/5/2026 | 21/7/2026 | QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a Man‑in‑the‑Middle (MITM) attack by impersonating the opensolution.org server and serving arbitrary HTML or JavaScript at the plugin list endpoint. When a user accesses the… | |
| Aplazada | Media (4.8) | 0.21% | — | QuickcmsAI | 29/5/2026 | 21/7/2026 | QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in a patch to version 6.8 published on… | |
| Aplazada | Crítica (9.9) | 0.55% | — | Ludwig YOU QuickwebpAI | 27/5/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly:… | |
| Aplazada | Media (5.1) | 0.18% | — | Opensolution Quick.cmsAI | 16/5/2026 | 17/6/2026 | Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arbitrary JavaScript… | |
| Aplazada | Alta (7.5) | 1.2% | — | Quick PlaygroundAI | 15/5/2026 | 17/6/2026 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the theme root directory path without sanitizing directory… | |
| Analizada | Alta (8.5) | 0.11% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Alta (8.5) | 0.11% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Media (6.8) | 0.10% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Analizada | Media (6.9) | 0.10% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Analizada | Media (6.8) | 0.10% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via… | |
| Analizada | Media (4.8) | 0.10% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur… | |
| Analizada | Media (6.9) | 0.10% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via… | |
| Analizada | Media (6.9) | 0.10% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Pendiente de análisis | Alta (8.5) | 0.11% | — | Intel Quickassist Adapter 8960 SoftwareAI | 12/5/2026 | 17/6/2026 | Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result… | |
| Analizada | Media (6.9) | 0.10% | — | Intel Quickassist Technology | 12/5/2026 | 17/6/2026 | Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Media (6.4) | 0.32% | — | Quick TableAI | 12/5/2026 | 17/6/2026 | The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.3) | 0.40% | — | Quickjs-ngAI | 11/5/2026 | 17/6/2026 | An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function | |
| Aplazada | Alta (7.2) | 0.39% | — | Quick Interest SliderAI | 15/4/2026 | 17/6/2026 | The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'loan-period' parameters in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Crítica (9.8) | 8.1% | — | Quick PlaygroundAI | 9/4/2026 | 17/6/2026 | The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve… | |
| Analizada | Media (5.3) | 0.27% | — | Roastslav Quickdrop | 7/4/2026 | 17/6/2026 | QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file preview endpoint. The application allows SVG files to be uploaded via the /api/file/upload-chunk endpoint. An attacker can upload a specially crafted SVG file containing a JavaScript payload. When any… | |
| Analizada | Media (5.4) | 0.14% | — | Wim-leers Quick Edit | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit allows Cross-Site Scripting (XSS).This issue affects Quick Edit: from 0.0.0 before 1.0.5, from 2.0.0 before 2.0.1. | |
| Aplazada | Baja (1.9) | 0.16% | — | Quickjs-ng QuickjsAI | 12/3/2026 | 17/6/2026 | A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been published and may be used. Patch name: daab4ad4bae4ef071ed0294618d6244e92def4cd. Applying… | |
| Analizada | Alta (7.5) | 0.29% | — | Quickjs Project Quickjs | 6/3/2026 | 17/6/2026 | A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` interpreter using the `-m` option and a low memory limit can cause an out-of-memory condition followed by an assertion failure in JS_FreeRuntime… | |
| Analizada | Media (6.5) | 0.22% | — | Quickjs Project Quickjs | 6/3/2026 | 17/6/2026 | A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb5b552e6 (2025-12-11), in file gc_decref_child in quickjs.c, when executed with the qjs interpreter using the -m option. This leads to an abort (SIGABRT) during garbage… |