Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.64% | — | Quadbase Espressreports ES | 11/3/2021 | 17/6/2026 | An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses a POST request made to the DashboardBuilder within the target web application. This request will utilise the target admin session and perform the authenticated request (to change… | |
| Modificada | Media (6.1) | 0.84% | — | Quadient Mail Accounting | 28/10/2020 | 17/6/2026 | NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS. | |
| Modificada | Alta (8.8) | 6.5% | — | Quadra-informatique Atos/sips | 5/8/2020 | 17/6/2026 | The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection. | |
| Modificada | Media (4.7) | 0.27% | — | Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware+1 | 25/6/2020 | 17/6/2026 | NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service. | |
| Modificada | Media (5.5) | 0.35% | — | Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware | 25/6/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX 11 user mode driver (nvwgf2um/x.dll), in which a specially crafted shader can cause an out of bounds access, leading to denial of service. | |
| Modificada | Alta (7.8) | 0.35% | — | Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce ExperienceNvidia NVS Firmware+1 | 25/6/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or information disclosure. | |
| Modificada | Alta (7.8) | 0.47% | — | Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware+1 | 25/6/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure. | |
| Modificada | Alta (7.8) | 0.32% | — | Nvidia Quadro FirmwareNvidia Geforce FirmwareNvidia Tesla FirmwareNvidia NVS Firmware | 24/6/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component, in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges. | |
| Modificada | Alta (7.8) | 0.37% | — | Nvidia Quadro FirmwareNvidia Geforce ExperienceNvidia Tesla Firmware | 11/3/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can plant a malicious DLL file, which may lead to code execution, denial of service, or information disclosure. | |
| Modificada | Alta (7.8) | 0.32% | — | Nvidia Quadro FirmwareNvidia Geforce ExperienceNvidia Tesla Firmware | 5/3/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges. | |
| Modificada | Alta (8.8) | 0.69% | — | Quadlayers WP Social Feed Gallery | 29/8/2019 | 17/6/2026 | The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete. | |
| Modificada | Alta (8.8) | 0.78% | — | Quadbase Espressreport Enterprise Server | 24/6/2019 | 17/6/2026 | CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests. | |
| Modificada | Media (5.4) | 0.82% | — | Quadbase Espressreport ES | 24/6/2019 | 17/6/2026 | Stored XSS within Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The XSS payload is stored by creating a new user account, and setting the username to an XSS payload. The stored payload can then be triggered… | |
| Modificada | Media (6.5) | 1.4% | — | Canonical Ubuntu LinuxNvidia Geforce GTX 745 FirmwareNvidia Geforce GTX 750 FirmwareNvidia Geforce GTX 750 TI Firmware+13 | 1/4/2019 | 17/6/2026 | A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-service issues. An attacker can provide a specially crafted website to trigger this vulnerability.… | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Squadmanagement Project Squadmanagement | 17/2/2018 | 17/6/2026 | SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter. | |
| Modificada | Media (6.3) | 0.34% | — | NXP Vybrid Mvf30nn151cku26 FirmwareNXP Vybrid Mvf30ns151cku26 FirmwareNXP Vybrid Mvf50nn151cmk40 FirmwareNXP Vybrid Mvf50nn151cmk50 Firmware+23 | 7/8/2017 | 17/6/2026 | A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vybrid VF3xx, Vybrid VF5xx, and Vybrid VF6xx. When the device is configured in security enabled… | |
| Modificada | Media (6) | 0.26% | — | NXP Vybrid Mvf30nn151cku26 FirmwareNXP Vybrid Mvf30ns151cku26 FirmwareNXP Vybrid Mvf50nn151cmk40 FirmwareNXP Vybrid Mvf50nn151cmk50 Firmware+26 | 7/8/2017 | 17/6/2026 | An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is… | |
| Modificada | Media (5) | 1.6% | — | Quade Edit Limit | 16/7/2013 | 16/6/2026 | The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors. | |
| Modificada | Media (6.8) | 0.30% | — | Cisco Application Networking ManagerCisco Context Directory AgentCisco Identity Services Engine SoftwareCisco Network Services Manager+7 | 29/4/2013 | 16/6/2026 | The command-line interface in Cisco Secure Access Control System (ACS), Identity Services Engine Software, Context Directory Agent, Application Networking Manager (ANM), Prime Network Control System, Prime LAN Management Solution (LMS), Prime Collaboration, Unified Provisioning Manager, Network Services Manager, Prime… | |
| Modificada | Media (6.8) | 0.30% | — | Cisco Application Networking ManagerCisco Context Directory AgentCisco Identity Services Engine SoftwareCisco Network Services Manager+6 | 19/2/2013 | 16/6/2026 | The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prime LAN Management Solution (LMS), Prime Network Control System, Quad, Context Directory Agent, Prime Collaboration, Unified Provisioning Manager, and Network Services… | |
| Modificada | Media (4.3) | 0.94% | — | Cisco QuadCisco Webex Social | 17/1/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco WebEx Social (formerly Cisco Quad) allows remote attackers to inject arbitrary web script or HTML via a crafted RSS service link, aka Bug ID CSCub61977. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Quadcomm Q-shop | 24/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the srkeys parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Quadcomm Q-shop | 24/2/2009 | 16/6/2026 | SQL injection vulnerability in users.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the (1) UserID and (2) Pwd parameters. NOTE: this might be related to CVE-2004-2108. | |
| Modificada | Alta (7.5) | 5.1% | 💥 Exploit | Quadcomm Q-shop | 19/9/2006 | 16/6/2026 | SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL commands via the OrderBy parameter. | |
| Modificada | Alta (7.5) | 3.2% | — | Quadcomm Q-shop | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showcat.asp, (5) users.asp, (6) addtomylist.asp, (7) modline.asp, (8) cart.asp, or (9) newuser.asp. |