Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.37% | 💥 PoC | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. | |
| Aplazada | Alta (7.1) | 0.23% | — | Quantumcloud Simple Link DirectoryAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected XSS.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Aplazada | Alta (7.1) | 0.23% | — | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Reflected XSS.This issue affects Simple Business Directory Pro: from n/a through <= 15.5.1. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Quantum Dxi6702AI | 1/8/2025 | 17/6/2026 | XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304) devices via rest/Users?action=authenticate. | |
| Aplazada | Media (5.8) | 0.30% | — | Quantum Superloader 3AI | 1/8/2025 | 17/6/2026 | Quantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account because there are only 65536 possible passwords. | |
| Analizada | Media (5.5) | 0.22% | — | Openquantumsafe Liboqs | 10/7/2025 | 17/6/2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2,… | |
| Aplazada | Alta (8.5) | 0.29% | — | Quantumcloud Simple Link DirectoryAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows SQL Injection.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Aplazada | Media (4.3) | 0.27% | — | Quantumcloud ChatbotAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 6.7.3. | |
| Aplazada | Crítica (9.3) | 0.83% | — | Wavlink Quantum D2GAIWavlink Quantum D3GAIWavlink Wl-wn530g3aAIWavlink Wl-wn530hg3AI+2 | 1/6/2025 | 17/6/2026 | A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to V1410_240222 and classified as critical. Affected by this issue is the function sys_login of the file /cgi-bin/login.cgi of the component HTTP POST Request Handler. The manipulation of the argument… | |
| Analizada | Baja (3.7) | 0.24% | — | Openquantumsafe Liboqs | 30/5/2025 | 17/6/2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. liboqs prior to version 0.13.0 supports the HQC algorithm, an algorithm with a theoretical design flaw which leads to large numbers of malformed ciphertexts sharing the same implicit rejection value.… | |
| Aplazada | Crítica (9.8) | 0.49% | — | Quantumcloud Simple Business Directory PROAI | 23/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. | |
| Aplazada | Alta (7.7) | 0.53% | — | Quantumcloud KBX PRO UltimateAI | 23/5/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Path Traversal.This issue affects KBx Pro Ultimate: from n/a through < 8.0.5. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Quantumcloud Wpbot PROAI | 19/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This issue affects WPBot Pro Wordpress Chatbot: from n/a through 12.7.0. | |
| Aplazada | Media (5.3) | 0.31% | — | Quantumcloud Simple Link DirectoryAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Analizada | Media (4.8) | 0.26% | — | Quantumcloud Wpbot | 15/5/2025 | 17/6/2026 | The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Crítica (9.8) | 0.65% | — | Quantumcloud Simple Video Directory | 15/5/2025 | 17/6/2026 | The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Aplazada | Alta (7.2) | 0.29% | — | Quantum StornextAIQuantum Stornext RYOAIQuantum Stornext Xcellis Workflow DirectorAIQuantum Activescale Cold StorageAI | 25/4/2025 | 17/6/2026 | Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage. | |
| Aplazada | Crítica (9.9) | 0.74% | — | Quantum StornextAIQuantum Stornext RYOAIQuantum Stornext Xcellis Workflow DirectorAIQuantum Activescale Cold StorageAI | 25/4/2025 | 17/6/2026 | Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage. | |
| Aplazada | Media (6.5) | 0.31% | — | Quantumcloud SEO HelpAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in QuantumCloud SEO Help seo-help allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEO Help: from n/a through <= 6.7.9. | |
| Aplazada | Media (6.8) | 0.46% | — | Quantumcloud SEO HelpAI | 9/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in QuantumCloud SEO Help seo-help allows Server Side Request Forgery.This issue affects SEO Help: from n/a through <= 6.7.9. | |
| Aplazada | Media (5.8) | 0.23% | — | Post-quantum Secure Feldman S Verifiable Secret Sharing Feldman VSSAI | 14/3/2025 | 17/6/2026 | Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret Sharing (VSS) scheme. In versions 0.8.0b2 and prior, the `feldman_vss` library contains timing side-channel vulnerabilities in its matrix operations, specifically within the `_find_secure_pivot`… | |
| Aplazada | Media (5.4) | 0.18% | — | Post-quantum Secure Feldman S Verifiable Secret SharingAI | 14/3/2025 | 17/6/2026 | Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret Sharing (VSS) scheme. In versions 0.8.0b2 and prior, the `secure_redundant_execution` function in feldman_vss.py attempts to mitigate fault injection attacks by executing a function multiple times… | |
| Aplazada | Alta (7.5) | 0.77% | — | Quantumcloud ChatbotAI | 25/2/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QuantumCloud ChatBot chatbot allows PHP Local File Inclusion.This issue affects ChatBot: from n/a through <= 6.3.5. | |
| Analizada | Media (4.3) | 0.27% | — | Quantumcloud Wpot | 22/1/2025 | 17/6/2026 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'qc_wp_latest_update_check_pro' function in all versions up to, and including, 13.5.5. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.5) | 0.23% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot conversational-forms allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through <= 1.4.2. |