Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.19% | — | Opensolution Quick.cms | 23/10/2025 | 17/6/2026 | QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user is not able to add JavaScript into the website. The vendor was… | |
| Analizada | Media (4.8) | 0.19% | — | Opensolution Quick.cms | 23/10/2025 | 17/6/2026 | QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website. The vendor… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpclever WPC Smart Quick ViewAI | 18/10/2025 | 17/6/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data… | |
| Analizada | Alta (7.1) | 0.48% | — | Quickjs Project Quickjs | 16/10/2025 | 17/6/2026 | A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to create a BigInt from a string with an excessively large number of digits. The function calculates the necessary number of bits (n_bits) required to store the BigInt using the formula: $$\text{n\_bits}… | |
| Analizada | Alta (7.1) | 0.46% | — | Quickjs Project Quickjs | 16/10/2025 | 17/6/2026 | An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent representation of the bytecode buffer size. | |
| Analizada | Alta (7.1) | 0.51% | — | Quickjs Project Quickjs | 16/10/2025 | 17/6/2026 | A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. This mismatch between the assumed type (string) and the actual type allows an attacker to control the data structure being processed by the concatenation logic, resulting in a type confusion condition.… | |
| Analizada | Media (5.9) | 0.38% | — | Quickjs Project Quickjs | 16/10/2025 | 17/6/2026 | A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect calculation of the required number of digits, which in turn leads to reading memory past the allocated BigInt structure. $$ \\ \text{n\_digits} = (\text{n\_bits} + \text{log2\_radix} - 1) /… | |
| Analizada | Media (5.9) | 0.39% | — | Quickjs Project Quickjs | 16/10/2025 | 17/6/2026 | A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation of TypedArray.prototype.indexOf() when a negative fromIndex argument is supplied. $$d_{new} = d + \text{len}$$ This allows an attacker to cause an Out-of-Bounds Read of one element immediately… | |
| Analizada | Alta (8.8) | 0.41% | — | Quickjs Project Quickjs | 16/10/2025 | 17/6/2026 | A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promises (ts->rejected_promise_list). | |
| Analizada | Alta (8.8) | 0.41% | — | Quickjs Project Quickjs | 16/10/2025 | 17/6/2026 | In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over it. The issue is, printing a value is not side-effect free. An attacker-defined callback could run during js_print_value, during which the array could get resized and len1 become out of bounds. This… | |
| Aplazada | Media (6.4) | 0.29% | — | Quick Social LoginAI | 15/10/2025 | 17/6/2026 | The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' shortcode in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.24% | — | Quick Featured ImagesAI | 15/10/2025 | 17/6/2026 | The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail and qfi_delete_thumbnail AJAX actions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 0.45% | 💥 PoC | Nicehash Quickminer | 30/9/2025 | 17/6/2026 | NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary executables that are automatically executed, resulting in full remote… | |
| Aplazada | Media (6.5) | 0.22% | — | Shapedplugin LLC Quick View FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Quick View for WooCommerce woo-quickview allows Stored XSS.This issue affects Quick View for WooCommerce: from n/a through <= 2.2.16. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpbean WPB Quick View FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Quick View for WooCommerce woocommerce-lightbox allows Stored XSS.This issue affects WPB Quick View for WooCommerce: from n/a through <= 2.1.8. | |
| Aplazada | Media (4.3) | 0.13% | — | Fullworksplugins Quick Paypal PaymentsAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in fullworks Quick Paypal Payments quick-paypal-payments allows Cross Site Request Forgery.This issue affects Quick Paypal Payments: from n/a through <= 5.7.46. | |
| Aplazada | Alta (7.1) | 0.12% | — | Quick-event-calendarAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Stored XSS.This issue affects Quick Event Calendar: from n/a through <= 1.4.9. | |
| Analizada | Media (5.1) | 0.25% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notified early about this vulnerability, but didn't respond with… | |
| Analizada | Media (5.3) | 0.19% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the… | |
| Analizada | Media (5.3) | 0.19% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website.… | |
| Analizada | Media (6.9) | 0.14% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version… | |
| Analizada | Media (6.9) | 0.15% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified early about this vulnerability, but didn't respond with the details of… | |
| Analizada | Media (5.1) | 0.25% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notified early about this vulnerability, but didn't respond with the… | |
| Aplazada | Alta (8.4) | 0.35% | 💥 Exploit | MJM QuickplayerAI | 20/8/2025 | 16/6/2026 | MJM QuickPlayer (also known as MJM Player) version 2010 contains a stack-based buffer overflow vulnerability triggered by opening a malicious .s3m music file. The flaw occurs due to improper bounds checking in the file parser, allowing an attacker to overwrite memory and execute arbitrary code. Exploitation is… | |
| Analizada | Media (4.6) | 0.23% | — | Opensolution Quick.cms.ext | 20/8/2025 | 17/6/2026 | QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality. An attacker can craft a malicious URL that results in arbitrary JavaScript execution in the victim's browser when opened. The vendor was notified early about this vulnerability, but didn't respond with the details of… |