Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.31% | — | Quantumcloud HighlightAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Highlight highlight allows Stored XSS.This issue affects Highlight: from n/a through <= 2.0.2. | |
| Aplazada | Media (5.3) | 0.47% | — | Quantumcloud Floating Action ButtonsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in QuantumCloud Floating Action Buttons floating-action-buttons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Floating Action Buttons: from n/a through <= 0.9.1. | |
| Aplazada | Media (6.5) | 0.48% | — | Quantumcloud Simple Link DirectoryAI | 13/12/2024 | 17/6/2026 | The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.4.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated… | |
| Analizada | Alta (7.5) | 0.40% | — | Openquantumsafe Liboqs | 6/12/2024 | 17/6/2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference implementation of the HQC key encapsulation mechanism. Due to an indexing error, part of the secret key is incorrectly treated as non-secret data.… | |
| Aplazada | Media (5.3) | 0.42% | — | Quantumcloud Floating Buttons FOR WoocommerceAI | 19/11/2024 | 17/6/2026 | Missing Authorization vulnerability in QuantumCloud Floating Buttons for WooCommerce shop-assistant-for-woocommerce-jarvis allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Floating Buttons for WooCommerce: from n/a through <= 2.8.8. | |
| Modificada | Media (4.8) | 0.33% | — | Quantumcloud Wpbot | 17/7/2024 | 17/6/2026 | The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Modificada | Media (5.4) | 0.34% | — | Quantumcloud Simple Video Directory | 12/7/2024 | 17/6/2026 | The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Alta (8.2) | 0.45% | — | Oqs-providerAIOpensslAIOpenquantumsafe LiboqsAI | 17/6/2024 | 17/6/2026 | oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handles lengths decoded with DECODE_UINT32 at the start of serialized hybrid… | |
| Analizada | Alta (7.5) | 0.52% | — | Openquantumsafe Liboqs | 10/6/2024 | 17/6/2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A control-flow timing lean has been identified in the reference implementation of the Kyber key encapsulation mechanism when it is compiled with Clang 15-18 for `-Os`, `-O1`, and other compilation… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wavlink Quantum D2GAI | 28/5/2024 | 17/6/2026 | An issue discovered in Wavlink QUANTUM D2G routers allows attackers to hijack TCP sessions which could lead to a denial of service. | |
| Analizada | Alta (8.6) | 100% | ⚠ Explotación activa💥 Exploit | Checkpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security | 28/5/2024 | 5/8/2026 | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. | |
| Analizada | Crítica (9.8) | 0.62% | — | Openquantumsafe Liboqs | 24/5/2024 | 17/6/2026 | An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /pqcrystals-dilithium-standard_ml-dsa-44-ipd_avx2/sign.c component. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Prodys Quantum AudioAI | 23/5/2024 | 17/6/2026 | Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application. | |
| Modificada | Alta (7.7) | 0.36% | — | Quantumcloud Wpbot | 22/5/2024 | 17/6/2026 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete files… | |
| Modificada | Alta (7.7) | 0.36% | — | Quantumcloud Wpbot | 22/5/2024 | 17/6/2026 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files… | |
| Modificada | Media (5) | 0.38% | — | Quantumcloud Wpbot | 22/5/2024 | 17/6/2026 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to list files existing in… | |
| Aplazada | Media (6.5) | 0.35% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.2.0. | |
| Aplazada | Media (6.5) | 0.34% | — | Quantumcloud Infographic Maker IlistAI | 22/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Infographic Maker – iList allows Stored XSS.This issue affects Infographic Maker – iList: from n/a through 4.6.6. | |
| Aplazada | Media (5.9) | 0.34% | — | Quantumcloud Slider HeroAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quantum Cloud Slider Hero allows Stored XSS.This issue affects Slider Hero: from n/a through 8.6.1. | |
| Aplazada | Media (5.6) | 0.32% | — | Dormakaba Saflok MTAIDormakaba ConfidantAIDormakaba QuantumAIDormakaba SaffireAI+1 | 21/3/2024 | 17/6/2026 | The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the attacker has obtained one active or expired keycard for the specific property, aka the "Unsaflok" issue. This occurs, in part, because the key derivation function… | |
| Modificada | Crítica (9.8) | 0.52% | — | Quantumcloud Wpbot | 24/1/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0. | |
| Modificada | Alta (7.2) | 0.73% | — | Quantumcloud Wpbot | 19/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud AI ChatBot.This issue affects AI ChatBot: from n/a through 4.7.8. | |
| Modificada | Crítica (9.8) | 0.81% | — | Johnsoncontrols Quantum HD Unity Compressor FirmwareJohnsoncontrols Quantum HD Unity Acuair FirmwareJohnsoncontrols Quantum HD Unity Condenser/vessel FirmwareJohnsoncontrols Quantum HD Unity Evaporator Firmware+2 | 10/11/2023 | 17/6/2026 | An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed. | |
| Modificada | Media (4.8) | 0.32% | — | Quantumcloud Wpbot | 2/11/2023 | 17/6/2026 | The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in… | |
| Modificada | Media (5.4) | 0.21% | — | Quantumcloud Wpbot | 20/10/2023 | 17/6/2026 | The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to missing or incorrect nonce validation on the corresponding functions. This makes it possible for unauthenticated attackers to invoke those functions via a forged request… |