Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

844 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.24%—Wpclever WPC Smart Quick ViewAI20/8/202517/6/2026
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaMedia (6.8)0.14%—Intel Quickassist Technology12/8/202517/6/2026
Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaAlta (8.7)0.40%—Cloudflare Quiche7/8/202517/6/2026
Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000 https://datatracker.ietf.org/doc/html/rfc9000#section-5.1 . Once the QUIC handshake completes, a…
AnalizadaAlta (7.5)0.80%💥 PoCLitespeedtech Litespeed WEB ADCLitespeedtech Litespeed WEB ServerLitespeedtech LsquicLitespeedtech Openlitespeed1/8/202517/6/2026
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
AplazadaMedia (5.4)0.15%—Lenovo Trackpoint Quick MenuAI17/7/202517/6/2026
A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges.
AplazadaMedia (5.9)0.25%—Robert Cummings Quick FaviconAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Cummings Quick Favicon quick-favicon allows Stored XSS.This issue affects Quick Favicon: from n/a through <= 0.22.8.
AnalizadaAlta (7.5)0.94%—Cloudflare Quiche18/6/202517/6/2026
Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a handshake and initiating a…
AnalizadaMedia (5.3)0.86%—Cloudflare Quiche18/6/202517/6/2026
Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a handshake and initiating a…
AnalizadaMedia (5.3)0.27%—Quick Node Block Project Quick Node Block11/6/202517/6/2026
Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.
AnalizadaMedia (5.3)0.27%—Quick Node Block Project Quick Node Block11/6/202517/6/2026
Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.
AplazadaMedia (4.3)0.16%—Michael Cannon Custom Bulkquick EditAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Michael Cannon Custom Bulk/Quick Edit custom-bulkquick-edit allows Cross Site Request Forgery.This issue affects Custom Bulk/Quick Edit: from n/a through <= 1.6.10.
AplazadaMedia (4.3)0.16%—Quick-event-calendarAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Cross Site Request Forgery.This issue affects Quick Event Calendar: from n/a through <= 1.4.9.
AplazadaMedia (5.3)0.26%—Quickcabwp QuickcabAI6/6/202517/6/2026
Missing Authorization vulnerability in QuickcabWP QuickCab.This issue affects QuickCab: from n/a through 1.3.3.
AplazadaAlta (7.5)0.48%—Quic-goAI2/6/202517/6/2026
quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added in the v0.50.0 release can be used to trigger a nil-pointer dereference by a malicious QUIC client. In order to do so, the attacker first sends valid QUIC packets from different remote addresses…
AplazadaAlta (7.1)0.22%—Fullworksplugins Quick Contact FormAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Reflected XSS.This issue affects Quick Contact Form: from n/a through <= 8.2.1.
AplazadaAlta (8.8)0.24%—Thememove QuickcalAI16/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal - Appointment Booking Calendar for WordPress quickcal allows Privilege Escalation.This issue affects QuickCal - Appointment Booking Calendar for WordPress: from n/a through <= 1.0.15.
AplazadaMedia (4.3)0.34%—Themovation Quickcal - Appointment Booking Calendar FOR WordpressAI16/5/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themovation QuickCal - Appointment Booking Calendar for WordPress quickcal allows Retrieve Embedded Sensitive Data.This issue affects QuickCal - Appointment Booking Calendar for WordPress: from n/a through <= 1.0.15.
AplazadaMedia (5.3)0.57%—Vector4wang Spring-boot-quickAI10/5/202517/6/2026
A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue affects the function ResponseEntity of the file /spring-boot-quick-master/quick-img2txt/src/main/java/com/quick/controller/Img2TxtController.java of the component quick-img2txt. The manipulation leads…
AplazadaMedia (5.3)1.0%—Rust RingAIQuicAI9/5/202530/6/2026
A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.
AplazadaMedia (6.9)0.48%—Quick Agent V3AIQuick Agent V2AI28/4/202517/6/2026
Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, a remote unauthenticated attacker may attempt to log in to an arbitrary host via Windows system where the product is running.
AplazadaAlta (7.1)0.69%—Quick Agent V3AIQuick Agent V2AI28/4/202517/6/2026
Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, an arbitrary file in the affected product may be obtained by a remote attacker who can log in to the product.
AplazadaCrítica (9.2)0.86%—Quick Agent V3AIQuick Agent V2AI28/4/202517/6/2026
Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, arbitrary code may be executed by a remote unauthenticated attacker with the Windows system privilege where the product is running.
AnalizadaAlta (8.4)0.32%—Quickjs-ng QuickjsQuickjs Project Quickjs27/4/202517/6/2026
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
AnalizadaAlta (7.8)0.30%—Bellard QuickjsQuickjs-ng Quickjs27/4/202517/6/2026
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
AplazadaAlta (7.1)0.29%—Rtowebsites AdminquickbarAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtowebsites AdminQuickbar adminquickbar allows Reflected XSS.This issue affects AdminQuickbar: from n/a through <= 1.9.1.
Orbitaley — Vulnerabilidades