Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
844 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.24% | — | Wpclever WPC Smart Quick ViewAI | 20/8/2025 | 17/6/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.8) | 0.14% | — | Intel Quickassist Technology | 12/8/2025 | 17/6/2026 | Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Alta (8.7) | 0.40% | — | Cloudflare Quiche | 7/8/2025 | 17/6/2026 | Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000 https://datatracker.ietf.org/doc/html/rfc9000#section-5.1 . Once the QUIC handshake completes, a… | |
| Analizada | Alta (7.5) | 0.80% | 💥 PoC | Litespeedtech Litespeed WEB ADCLitespeedtech Litespeed WEB ServerLitespeedtech LsquicLitespeedtech Openlitespeed | 1/8/2025 | 17/6/2026 | LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak. | |
| Aplazada | Media (5.4) | 0.15% | — | Lenovo Trackpoint Quick MenuAI | 17/7/2025 | 17/6/2026 | A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges. | |
| Aplazada | Media (5.9) | 0.25% | — | Robert Cummings Quick FaviconAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Cummings Quick Favicon quick-favicon allows Stored XSS.This issue affects Quick Favicon: from n/a through <= 0.22.8. | |
| Analizada | Alta (7.5) | 0.94% | — | Cloudflare Quiche | 18/6/2025 | 17/6/2026 | Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a handshake and initiating a… | |
| Analizada | Media (5.3) | 0.86% | — | Cloudflare Quiche | 18/6/2025 | 17/6/2026 | Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a handshake and initiating a… | |
| Analizada | Media (5.3) | 0.27% | — | Quick Node Block Project Quick Node Block | 11/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0. | |
| Analizada | Media (5.3) | 0.27% | — | Quick Node Block Project Quick Node Block | 11/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Michael Cannon Custom Bulkquick EditAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Cannon Custom Bulk/Quick Edit custom-bulkquick-edit allows Cross Site Request Forgery.This issue affects Custom Bulk/Quick Edit: from n/a through <= 1.6.10. | |
| Aplazada | Media (4.3) | 0.16% | — | Quick-event-calendarAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Cross Site Request Forgery.This issue affects Quick Event Calendar: from n/a through <= 1.4.9. | |
| Aplazada | Media (5.3) | 0.26% | — | Quickcabwp QuickcabAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in QuickcabWP QuickCab.This issue affects QuickCab: from n/a through 1.3.3. | |
| Aplazada | Alta (7.5) | 0.48% | — | Quic-goAI | 2/6/2025 | 17/6/2026 | quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added in the v0.50.0 release can be used to trigger a nil-pointer dereference by a malicious QUIC client. In order to do so, the attacker first sends valid QUIC packets from different remote addresses… | |
| Aplazada | Alta (7.1) | 0.22% | — | Fullworksplugins Quick Contact FormAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Reflected XSS.This issue affects Quick Contact Form: from n/a through <= 8.2.1. | |
| Aplazada | Alta (8.8) | 0.24% | — | Thememove QuickcalAI | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal - Appointment Booking Calendar for WordPress quickcal allows Privilege Escalation.This issue affects QuickCal - Appointment Booking Calendar for WordPress: from n/a through <= 1.0.15. | |
| Aplazada | Media (4.3) | 0.34% | — | Themovation Quickcal - Appointment Booking Calendar FOR WordpressAI | 16/5/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themovation QuickCal - Appointment Booking Calendar for WordPress quickcal allows Retrieve Embedded Sensitive Data.This issue affects QuickCal - Appointment Booking Calendar for WordPress: from n/a through <= 1.0.15. | |
| Aplazada | Media (5.3) | 0.57% | — | Vector4wang Spring-boot-quickAI | 10/5/2025 | 17/6/2026 | A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue affects the function ResponseEntity of the file /spring-boot-quick-master/quick-img2txt/src/main/java/com/quick/controller/Img2TxtController.java of the component quick-img2txt. The manipulation leads… | |
| Aplazada | Media (5.3) | 1.0% | — | Rust RingAIQuicAI | 9/5/2025 | 30/6/2026 | A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received. | |
| Aplazada | Media (6.9) | 0.48% | — | Quick Agent V3AIQuick Agent V2AI | 28/4/2025 | 17/6/2026 | Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, a remote unauthenticated attacker may attempt to log in to an arbitrary host via Windows system where the product is running. | |
| Aplazada | Alta (7.1) | 0.69% | — | Quick Agent V3AIQuick Agent V2AI | 28/4/2025 | 17/6/2026 | Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, an arbitrary file in the affected product may be obtained by a remote attacker who can log in to the product. | |
| Aplazada | Crítica (9.2) | 0.86% | — | Quick Agent V3AIQuick Agent V2AI | 28/4/2025 | 17/6/2026 | Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, arbitrary code may be executed by a remote unauthenticated attacker with the Windows system privilege where the product is running. | |
| Analizada | Alta (8.4) | 0.32% | — | Quickjs-ng QuickjsQuickjs Project Quickjs | 27/4/2025 | 17/6/2026 | quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected. | |
| Analizada | Alta (7.8) | 0.30% | — | Bellard QuickjsQuickjs-ng Quickjs | 27/4/2025 | 17/6/2026 | quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected. | |
| Aplazada | Alta (7.1) | 0.29% | — | Rtowebsites AdminquickbarAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtowebsites AdminQuickbar adminquickbar allows Reflected XSS.This issue affects AdminQuickbar: from n/a through <= 1.9.1. |