Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

197 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.31%—Quantumcloud HighlightAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Highlight highlight allows Stored XSS.This issue affects Highlight: from n/a through <= 2.0.2.
AplazadaMedia (5.3)0.47%—Quantumcloud Floating Action ButtonsAI2/1/202517/6/2026
Missing Authorization vulnerability in QuantumCloud Floating Action Buttons floating-action-buttons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Floating Action Buttons: from n/a through <= 0.9.1.
AplazadaMedia (6.5)0.48%—Quantumcloud Simple Link DirectoryAI13/12/202417/6/2026
The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.4.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated…
AnalizadaAlta (7.5)0.40%—Openquantumsafe Liboqs6/12/202417/6/2026
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference implementation of the HQC key encapsulation mechanism. Due to an indexing error, part of the secret key is incorrectly treated as non-secret data.…
AplazadaMedia (5.3)0.42%—Quantumcloud Floating Buttons FOR WoocommerceAI19/11/202417/6/2026
Missing Authorization vulnerability in QuantumCloud Floating Buttons for WooCommerce shop-assistant-for-woocommerce-jarvis allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Floating Buttons for WooCommerce: from n/a through <= 2.8.8.
ModificadaMedia (4.8)0.33%—Quantumcloud Wpbot17/7/202417/6/2026
The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…
ModificadaMedia (5.4)0.34%—Quantumcloud Simple Video Directory12/7/202417/6/2026
The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaAlta (8.2)0.45%—Oqs-providerAIOpensslAIOpenquantumsafe LiboqsAI17/6/202417/6/2026
oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handles lengths decoded with DECODE_UINT32 at the start of serialized hybrid…
AnalizadaAlta (7.5)0.52%—Openquantumsafe Liboqs10/6/202417/6/2026
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A control-flow timing lean has been identified in the reference implementation of the Kyber key encapsulation mechanism when it is compiled with Clang 15-18 for `-Os`, `-O1`, and other compilation…
AplazadaAlta (7.5)0.42%—Wavlink Quantum D2GAI28/5/202417/6/2026
An issue discovered in Wavlink QUANTUM D2G routers allows attackers to hijack TCP sessions which could lead to a denial of service.
AnalizadaAlta (8.6)100%⚠ Explotación activa💥 ExploitCheckpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security28/5/20245/8/2026
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
AnalizadaCrítica (9.8)0.62%—Openquantumsafe Liboqs24/5/202417/6/2026
An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /pqcrystals-dilithium-standard_ml-dsa-44-ipd_avx2/sign.c component.
AplazadaCrítica (9.8)0.53%—Prodys Quantum AudioAI23/5/202417/6/2026
Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application.
ModificadaAlta (7.7)0.36%—Quantumcloud Wpbot22/5/202417/6/2026
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete files…
ModificadaAlta (7.7)0.36%—Quantumcloud Wpbot22/5/202417/6/2026
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files…
ModificadaMedia (5)0.38%—Quantumcloud Wpbot22/5/202417/6/2026
The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to list files existing in…
AplazadaMedia (6.5)0.35%—Quantumcloud Conversational Forms FOR ChatbotAI6/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.2.0.
AplazadaMedia (6.5)0.34%—Quantumcloud Infographic Maker IlistAI22/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Infographic Maker – iList allows Stored XSS.This issue affects Infographic Maker – iList: from n/a through 4.6.6.
AplazadaMedia (5.9)0.34%—Quantumcloud Slider HeroAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quantum Cloud Slider Hero allows Stored XSS.This issue affects Slider Hero: from n/a through 8.6.1.
AplazadaMedia (5.6)0.32%—Dormakaba Saflok MTAIDormakaba ConfidantAIDormakaba QuantumAIDormakaba SaffireAI+121/3/202417/6/2026
The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the attacker has obtained one active or expired keycard for the specific property, aka the "Unsaflok" issue. This occurs, in part, because the key derivation function…
ModificadaCrítica (9.8)0.52%—Quantumcloud Wpbot24/1/202417/6/2026
Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0.
ModificadaAlta (7.2)0.73%—Quantumcloud Wpbot19/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud AI ChatBot.This issue affects AI ChatBot: from n/a through 4.7.8.
ModificadaCrítica (9.8)0.81%—Johnsoncontrols Quantum HD Unity Compressor FirmwareJohnsoncontrols Quantum HD Unity Acuair FirmwareJohnsoncontrols Quantum HD Unity Condenser/vessel FirmwareJohnsoncontrols Quantum HD Unity Evaporator Firmware+210/11/202317/6/2026
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
ModificadaMedia (4.8)0.32%—Quantumcloud Wpbot2/11/202317/6/2026
The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in…
ModificadaMedia (5.4)0.21%—Quantumcloud Wpbot20/10/202317/6/2026
The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to missing or incorrect nonce validation on the corresponding functions. This makes it possible for unauthenticated attackers to invoke those functions via a forged request…
Orbitaley — Vulnerabilidades