Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.13% | — | Opensolution Quick.cms | 20/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious article with content defined by the attacker. The vendor was notified early about this… | |
| Analizada | Media (4.8) | 0.19% | — | Opensolution Quick.cms | 20/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. Regular admin user is not able to inject any JS scripts into the page. The vendor was… | |
| Aplazada | Media (6.4) | 0.24% | — | Wpclever WPC Smart Quick ViewAI | 20/8/2025 | 17/6/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.8) | 0.14% | — | Intel Quickassist Technology | 12/8/2025 | 17/6/2026 | Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (5.4) | 0.15% | — | Lenovo Trackpoint Quick MenuAI | 17/7/2025 | 17/6/2026 | A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges. | |
| Aplazada | Media (5.9) | 0.25% | — | Robert Cummings Quick FaviconAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Cummings Quick Favicon quick-favicon allows Stored XSS.This issue affects Quick Favicon: from n/a through <= 0.22.8. | |
| Analizada | Media (5.3) | 0.27% | — | Quick Node Block Project Quick Node Block | 11/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0. | |
| Analizada | Media (5.3) | 0.27% | — | Quick Node Block Project Quick Node Block | 11/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Michael Cannon Custom Bulkquick EditAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Cannon Custom Bulk/Quick Edit custom-bulkquick-edit allows Cross Site Request Forgery.This issue affects Custom Bulk/Quick Edit: from n/a through <= 1.6.10. | |
| Aplazada | Media (4.3) | 0.16% | — | Quick-event-calendarAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Cross Site Request Forgery.This issue affects Quick Event Calendar: from n/a through <= 1.4.9. | |
| Aplazada | Media (5.3) | 0.26% | — | Quickcabwp QuickcabAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in QuickcabWP QuickCab.This issue affects QuickCab: from n/a through 1.3.3. | |
| Aplazada | Alta (7.1) | 0.22% | — | Fullworksplugins Quick Contact FormAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Reflected XSS.This issue affects Quick Contact Form: from n/a through <= 8.2.1. | |
| Aplazada | Alta (8.8) | 0.24% | — | Thememove QuickcalAI | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal - Appointment Booking Calendar for WordPress quickcal allows Privilege Escalation.This issue affects QuickCal - Appointment Booking Calendar for WordPress: from n/a through <= 1.0.15. | |
| Aplazada | Media (4.3) | 0.34% | — | Themovation Quickcal - Appointment Booking Calendar FOR WordpressAI | 16/5/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themovation QuickCal - Appointment Booking Calendar for WordPress quickcal allows Retrieve Embedded Sensitive Data.This issue affects QuickCal - Appointment Booking Calendar for WordPress: from n/a through <= 1.0.15. | |
| Aplazada | Media (5.3) | 0.57% | — | Vector4wang Spring-boot-quickAI | 10/5/2025 | 17/6/2026 | A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue affects the function ResponseEntity of the file /spring-boot-quick-master/quick-img2txt/src/main/java/com/quick/controller/Img2TxtController.java of the component quick-img2txt. The manipulation leads… | |
| Aplazada | Media (6.9) | 0.48% | — | Quick Agent V3AIQuick Agent V2AI | 28/4/2025 | 17/6/2026 | Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, a remote unauthenticated attacker may attempt to log in to an arbitrary host via Windows system where the product is running. | |
| Aplazada | Alta (7.1) | 0.69% | — | Quick Agent V3AIQuick Agent V2AI | 28/4/2025 | 17/6/2026 | Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, an arbitrary file in the affected product may be obtained by a remote attacker who can log in to the product. | |
| Aplazada | Crítica (9.2) | 0.86% | — | Quick Agent V3AIQuick Agent V2AI | 28/4/2025 | 17/6/2026 | Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, arbitrary code may be executed by a remote unauthenticated attacker with the Windows system privilege where the product is running. | |
| Analizada | Alta (8.4) | 0.32% | — | Quickjs-ng QuickjsQuickjs Project Quickjs | 27/4/2025 | 17/6/2026 | quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected. | |
| Analizada | Alta (7.8) | 0.30% | — | Bellard QuickjsQuickjs-ng Quickjs | 27/4/2025 | 17/6/2026 | quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected. | |
| Aplazada | Alta (7.1) | 0.29% | — | Rtowebsites AdminquickbarAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtowebsites AdminQuickbar adminquickbar allows Reflected XSS.This issue affects AdminQuickbar: from n/a through <= 1.9.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Crmperks Integration FOR Woocommerce AND QuickbooksAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for WooCommerce and QuickBooks wp-woocommerce-quickbooks allows Cross Site Request Forgery.This issue affects Integration for WooCommerce and QuickBooks: from n/a through <= 1.3.1. | |
| Aplazada | Alta (7.1) | 0.42% | — | Myworks WOO Sync FOR Quickbooks OnlineAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyWorks MyWorks WooCommerce Sync for QuickBooks Online myworks-woo-sync-for-quickbooks-online allows Reflected XSS.This issue affects MyWorks WooCommerce Sync for QuickBooks Online: from n/a through <= 2.9.1. | |
| Aplazada | Alta (8.5) | 0.45% | — | Randyjensen RJ QuickchartsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in randyjensen RJ Quickcharts rj-quickcharts allows SQL Injection.This issue affects RJ Quickcharts: from n/a through <= 0.6.1. | |
| Aplazada | Alta (7.1) | 0.29% | — | Name.ly Quick LocalizationAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Name.ly Quick Localization quick-localization allows Reflected XSS.This issue affects Quick Localization: from n/a through <= 0.1.0. |