Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
844 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.36% | — | Quic-go Project Quic-go | 11/12/2025 | 17/6/2026 | quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory allocation through quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large header field section (many unique header names and/or large… | |
| Aplazada | Media (4.3) | 0.13% | — | Fullworksplugins Quick Contact FormAI | 9/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Cross Site Request Forgery.This issue affects Quick Contact Form: from n/a through <= 8.2.5. | |
| Aplazada | Media (5.3) | 0.25% | — | Quick Interest SliderAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Graham Quick Interest Slider quick-interest-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Interest Slider: from n/a through <= 3.1.7. | |
| Aplazada | Alta (8.6) | 0.27% | — | QuickcmsAI | 2/12/2025 | 17/6/2026 | A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high-privileged user into aFilesDelete allows for Blind SQL Injection attacks. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable… | |
| Aplazada | Media (5.3) | 0.26% | — | Quick View FOR WoocommerceAI | 27/11/2025 | 17/6/2026 | The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX endpoint due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers to extract data from… | |
| Analizada | Media (6.9) | 0.27% | — | Opensolution Quick.cms | 14/11/2025 | 17/6/2026 | A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor… | |
| Analizada | Media (4.8) | 0.18% | — | Opensolution Quick.cms | 14/11/2025 | 17/6/2026 | QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user is not able to add JavaScript into the website. The vendor was… | |
| Aplazada | Media (4.3) | 0.20% | — | QuicqAI | 13/11/2025 | 17/6/2026 | The Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_wpqai_disconnect_quicq_afosto' AJAX endpoint in all versions up to, and including,… | |
| Analizada | Alta (7.3) | 0.13% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur… | |
| Analizada | Media (5.8) | 0.12% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Analizada | Media (6.8) | 0.12% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Untrusted pointer dereference for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially… | |
| Analizada | Media (4.8) | 0.11% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Improper conditions check for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Analizada | Media (5.7) | 0.10% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Out-of-bounds read for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access… | |
| Analizada | Media (4.8) | 0.11% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur… | |
| Analizada | Alta (7.3) | 0.12% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Analizada | Media (6.8) | 0.14% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Untrusted pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via… | |
| Analizada | Media (6.8) | 0.13% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Null pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Analizada | Media (6.8) | 0.13% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access… | |
| Aplazada | Media (4.9) | 0.31% | — | Quick Featured ImagesAI | 8/11/2025 | 17/6/2026 | The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all versions up to, and including, 13.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Baja (1.9) | 0.22% | — | Bellard Quickjs | 5/11/2025 | 17/6/2026 | A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The attack is restricted to local execution. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.1) | 0.21% | — | Quick CartAI | 30/10/2025 | 1/10/2026 | Quick.Cart is vulnerable to Cross-Site Request Forgery in product creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious product with content defined by the attacker. This software does not implement any… | |
| Aplazada | Alta (7.5) | 0.33% | — | QuickcreatorAI | 24/10/2025 | 17/6/2026 | The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key and subsequently use that to perform… | |
| Analizada | Media (4.8) | 0.19% | — | Opensolution Quick.cms | 23/10/2025 | 17/6/2026 | QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user is not able to add JavaScript into the website. The vendor was… | |
| Analizada | Media (4.8) | 0.19% | — | Opensolution Quick.cms | 23/10/2025 | 17/6/2026 | QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website. The vendor… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpclever WPC Smart Quick ViewAI | 18/10/2025 | 17/6/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data… |