Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

791 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Graham Quick Interest SliderAI27/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Graham Quick Interest Slider quick-interest-slider allows DOM-Based XSS.This issue affects Quick Interest Slider: from n/a through <= 3.1.5.
AplazadaMedia (4.3)0.16%—Xiaomi Quick APP FrameworkAI27/3/202517/6/2026
An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is caused by improper input validation and can be exploited by attackers tointent redriction.
AnalizadaMedia (5.3)0.70%—Quickjs-ng Quickjs21/3/202517/6/2026
A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulnerability is the function JS_GetRuntime of the file quickjs.c of the component qjs. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. Upgrading to version…
AplazadaMedia (5.3)0.30%—Sendquick EnteraAI14/3/202517/6/2026
SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter.
AplazadaMedia (6.5)0.28%—Randyjensen Rj-quickchartsAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in randyjensen RJ Quickcharts rj-quickcharts allows Stored XSS.This issue affects RJ Quickcharts: from n/a through <= 0.6.1.
AnalizadaAlta (7.3)0.24%—Intel Quickassist Technology12/2/202517/6/2026
Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.1)0.21%—Intel Quickassist Technology12/2/202517/6/2026
Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaMedia (5.4)0.20%—Intel Quickassist Technology12/2/202517/6/2026
Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.3)0.48%—Arshid Woo-quick-viewAI24/1/202517/6/2026
Missing Authorization vulnerability in Arshid WooCommerce Quick View woo-quick-view allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Quick View: from n/a through <= 1.1.1.
AplazadaCrítica (9.8)0.73%—Marko-m Quick CountAI22/1/202517/6/2026
Deserialization of Untrusted Data vulnerability in Marko-M Quick Count quick-count allows Object Injection.This issue affects Quick Count: from n/a through <= 3.00.
AplazadaAlta (7.1)0.34%—Perfectsolution WP Ecommerce QuickpayAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PerfectSolution WP eCommerce Quickpay wp-ecommerce-quickpay allows Reflected XSS.This issue affects WP eCommerce Quickpay: from n/a through <= 1.1.0.
AplazadaAlta (7.1)0.35%—Fahadmahmood WP Quick ShopAI13/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Quick Shop wp-quick-shop allows Reflected XSS.This issue affects WP Quick Shop: from n/a through <= 1.3.1.
AplazadaMedia (5.4)0.35%—Arulprasadj WP Quick Post DuplicatorAI9/12/202417/6/2026
Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through 2.0.
AplazadaAlta (7.5)0.76%—Fullworksplugins Quick Paypal PaymentsAI9/12/202417/6/2026
Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Paypal Payments: from n/a through 5.7.25.
AplazadaMedia (6.5)0.71%—Fullworksplugins Quick Contact FormAI9/12/202417/6/2026
Missing Authorization vulnerability in Fullworks Quick Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Contact Form : from n/a through 8.0.3.1.
AplazadaMedia (5.3)0.66%—Fullworksplugins Quick Event ManagerAI9/12/202417/6/2026
Missing Authorization vulnerability in Fullworks Quick Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Event Manager: from n/a through 9.7.4.
AplazadaMedia (6.1)0.27%—Quick License ManagerAI3/12/202417/6/2026
The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, and including, 2.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (4.3)0.34%—Samsung Quick Share3/12/202417/6/2026
Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.
AplazadaCrítica (9.1)0.82%—Opensolution Quick.cmsAI29/11/202417/6/2026
Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictions and download any file if it has the appropriate permissions outside of documentroot configured on the server via the aDirFiles%5B0%5D parameter in the admin.php page.…
AplazadaCrítica (9.8)0.56%—Rajesh Thanoch Quick LearnAI20/11/202417/6/2026
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoch Quick Learn quick-learn allows Object Injection.This issue affects Quick Learn: from n/a through <= 1.0.1.
AplazadaMedia (6.5)0.31%—Quickheal Antivirus PROAI18/11/202417/6/2026
Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.
AplazadaAlta (8.8)0.38%—Quickheal Antivirus PROAIQuickheal Total SecurityAI18/11/202417/6/2026
An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.
ModificadaAlta (8.8)0.92%💥 PoCAntonhoelstad WP Quick Setup18/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0.
AnalizadaMedia (5.9)0.39%—Google Quick Share7/11/202417/6/2026
There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is contained in this frame is written to disk in the Downloads…
AplazadaMedia (6.5)0.43%—ACF Quick Edit FieldsAI16/10/202417/6/2026
The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above.
Orbitaley — Vulnerabilidades