Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.21% | — | QuickcmsAI | 6/3/2026 | 4/8/2026 | QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges. This software does not implement any protection against this type of attack. All forms available in… | |
| Analizada | Media (6.5) | 0.14% | — | Fofolee Utools-quickcommand | 23/2/2026 | 17/6/2026 | An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3. | |
| Aplazada | Media (4.3) | 0.16% | — | WP Quick Contact USAI | 14/2/2026 | 17/6/2026 | The WP Quick Contact Us plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request… | |
| Aplazada | Alta (7) | 0.16% | — | Intel Quick Assist TechnologyAI | 10/2/2026 | 15/7/2026 | Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This… | |
| Aplazada | Media (6.8) | 0.10% | — | Intel Quick Assist TechnologyAI | 10/2/2026 | 17/6/2026 | Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Aplazada | Media (5.5) | 0.15% | — | MquickjsAI | 10/2/2026 | 17/6/2026 | An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted file to the get_mblock_size function at mquickjs.c. | |
| Aplazada | Alta (8.8) | 0.46% | — | QuickdateAI | 7/2/2026 | 17/6/2026 | QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries through the '_located' parameter in the find_matches endpoint. Attackers can inject UNION-based SQL statements to extract database information including user credentials, database name, and system version. | |
| Analizada | Media (6.9) | 0.29% | — | Opensolution Quick.cart | 5/2/2026 | 17/6/2026 | In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password in user editing page. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.7 was tested and… | |
| Analizada | Media (4.8) | 0.31% | — | Opensolution Quick.cart | 5/2/2026 | 17/6/2026 | Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was notified early about this vulnerability, but… | |
| Analizada | Alta (7.8) | 0.12% | — | Quickheal Total Security | 3/2/2026 | 17/6/2026 | A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local… | |
| Aplazada | Alta (8.4) | 0.80% | — | Quick PlayerAI | 30/1/2026 | 17/6/2026 | Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with carefully constructed payload. Attackers can trigger the vulnerability by loading a specially crafted file through the application's file loading mechanism, potentially… | |
| Aplazada | Alta (8.5) | 0.18% | — | Quick N Easy FTP ServiceAI | 27/1/2026 | 17/6/2026 | Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code during service startup. Attackers can exploit the misconfigured service binary path to inject malicious executables with elevated LocalSystem privileges during system boot or service… | |
| Aplazada | Media (5.3) | 0.38% | — | Liuyueyi Quick-mediaAI | 27/1/2026 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/util modules). This vulnerability is associated with program files SeekableOutputStream.Java. This issue affects quick-media: before v1.0. | |
| Aplazada | Media (5.3) | 0.47% | — | Liuyueyi Quick-mediaAIApache BatikAI | 27/1/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/png modules). This vulnerability is associated with program files PNGImageEncoder.Java. This issue affects quick-media: before v1.0. | |
| Aplazada | Media (4.3) | 0.18% | — | AdminquickbarAI | 24/1/2026 | 17/6/2026 | The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.3. This is due to missing or incorrect nonce validation on the 'saveSettings' and 'renamePost' AJAX actions. This makes it possible for unauthenticated attackers to modify plugin settings and… | |
| Aplazada | Media (5.3) | 0.30% | — | Thingsforrestaurants Quick Restaurant ReservationsAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Alejandro Quick Restaurant Reservations quick-restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Restaurant Reservations: from n/a through <= 1.6.7. | |
| Aplazada | Media (4.3) | 0.24% | — | Arulprasadj WP Quick Post DuplicatorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator wp-quick-post-duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through <= 2.1. | |
| Analizada | Crítica (9.4) | 0.83% | — | Opensolution Quick.cart | 22/1/2026 | 17/6/2026 | Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to upload arbitrary file contents while only validating the filename extension. This allows an attacker to include and execute uploaded PHP code, resulting in Remote Code… | |
| Analizada | Media (5.1) | 0.29% | — | Opensolution Quick.cart | 22/1/2026 | 17/6/2026 | Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when opened, results in arbitrary JavaScript execution in the victim’s browser. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable… | |
| Modificada | Baja (2.1) | 0.40% | — | Quickjs-ng Quickjs | 19/1/2026 | 17/6/2026 | A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch… | |
| Modificada | Baja (2.1) | 0.41% | — | Quickjs-ng Quickjs | 19/1/2026 | 17/6/2026 | A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as… | |
| Aplazada | Media (5.8) | 0.23% | — | Fullworksplugins Quick Contact FormAI | 17/1/2026 | 17/6/2026 | The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6. This is due to the 'qcf_validate_form' AJAX endpoint allowing a user controlled parameter to set the 'from' email address. This makes it possible for unauthenticated attackers to send emails to… | |
| Modificada | Baja (2.1) | 0.46% | — | Quickjs-ng Quickjs | 10/1/2026 | 17/6/2026 | A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the… | |
| Modificada | Media (5.5) | 0.52% | — | Quickjs-ng Quickjs | 10/1/2026 | 17/6/2026 | A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.… | |
| Aplazada | Media (5.3) | 0.25% | — | Addonify Quick ViewAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Addonify Addonify addonify-quick-view allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify: from n/a through <= 2.0.4. |