Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.12% | — | Meks Quick Plugin DisablerAI | 16/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cross Site Request Forgery.This issue affects Meks Quick Plugin Disabler: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.13% | — | Graham Quick Interest SliderAI | 16/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Graham Quick Interest Slider quick-interest-slider allows Cross Site Request Forgery.This issue affects Quick Interest Slider: from n/a through <= 3.1.5. | |
| Aplazada | Media (6.4) | 0.29% | — | Yithemes Yith Woocommerce Quick ViewAI | 13/12/2025 | 17/6/2026 | The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_quick_view shortcode in all versions up to, and including, 2.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.4) | 0.18% | — | Quick TestimonialsAI | 13/12/2025 | 17/6/2026 | The Quick Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Analizada | Crítica (9.3) | 0.67% | — | Opensolution Quick CMS | 11/12/2025 | 17/6/2026 | Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system. | |
| Aplazada | Media (4.3) | 0.13% | — | Fullworksplugins Quick Contact FormAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Cross Site Request Forgery.This issue affects Quick Contact Form: from n/a through <= 8.2.5. | |
| Aplazada | Media (5.3) | 0.25% | — | Quick Interest SliderAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Graham Quick Interest Slider quick-interest-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Interest Slider: from n/a through <= 3.1.7. | |
| Aplazada | Alta (8.6) | 0.27% | — | QuickcmsAI | 2/12/2025 | 17/6/2026 | A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high-privileged user into aFilesDelete allows for Blind SQL Injection attacks. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable… | |
| Aplazada | Media (5.3) | 0.26% | — | Quick View FOR WoocommerceAI | 27/11/2025 | 17/6/2026 | The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX endpoint due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers to extract data from… | |
| Analizada | Media (6.9) | 0.27% | — | Opensolution Quick.cms | 14/11/2025 | 17/6/2026 | A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor… | |
| Analizada | Media (4.8) | 0.18% | — | Opensolution Quick.cms | 14/11/2025 | 17/6/2026 | QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user is not able to add JavaScript into the website. The vendor was… | |
| Analizada | Alta (7.3) | 0.13% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur… | |
| Analizada | Media (5.8) | 0.12% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Analizada | Media (6.8) | 0.12% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Untrusted pointer dereference for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially… | |
| Analizada | Media (4.8) | 0.11% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Improper conditions check for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Analizada | Media (5.7) | 0.10% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Out-of-bounds read for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access… | |
| Analizada | Media (4.8) | 0.11% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur… | |
| Analizada | Alta (7.3) | 0.12% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Analizada | Media (6.8) | 0.14% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Untrusted pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via… | |
| Analizada | Media (6.8) | 0.13% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Null pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Analizada | Media (6.8) | 0.13% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access… | |
| Aplazada | Media (4.9) | 0.31% | — | Quick Featured ImagesAI | 8/11/2025 | 17/6/2026 | The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all versions up to, and including, 13.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Baja (1.9) | 0.22% | — | Bellard Quickjs | 5/11/2025 | 17/6/2026 | A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The attack is restricted to local execution. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.1) | 0.21% | — | Quick CartAI | 30/10/2025 | 1/10/2026 | Quick.Cart is vulnerable to Cross-Site Request Forgery in product creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious product with content defined by the attacker. This software does not implement any… | |
| Aplazada | Alta (7.5) | 0.33% | — | QuickcreatorAI | 24/10/2025 | 17/6/2026 | The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key and subsequently use that to perform… |