Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Graham Quick Interest SliderAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Graham Quick Interest Slider quick-interest-slider allows DOM-Based XSS.This issue affects Quick Interest Slider: from n/a through <= 3.1.5. | |
| Aplazada | Media (4.3) | 0.16% | — | Xiaomi Quick APP FrameworkAI | 27/3/2025 | 17/6/2026 | An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is caused by improper input validation and can be exploited by attackers tointent redriction. | |
| Analizada | Media (5.3) | 0.70% | — | Quickjs-ng Quickjs | 21/3/2025 | 17/6/2026 | A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulnerability is the function JS_GetRuntime of the file quickjs.c of the component qjs. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. Upgrading to version… | |
| Aplazada | Media (5.3) | 0.30% | — | Sendquick EnteraAI | 14/3/2025 | 17/6/2026 | SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter. | |
| Aplazada | Media (6.5) | 0.28% | — | Randyjensen Rj-quickchartsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in randyjensen RJ Quickcharts rj-quickcharts allows Stored XSS.This issue affects RJ Quickcharts: from n/a through <= 0.6.1. | |
| Analizada | Alta (7.3) | 0.24% | — | Intel Quickassist Technology | 12/2/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.1) | 0.21% | — | Intel Quickassist Technology | 12/2/2025 | 17/6/2026 | Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Media (5.4) | 0.20% | — | Intel Quickassist Technology | 12/2/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.3) | 0.48% | — | Arshid Woo-quick-viewAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Arshid WooCommerce Quick View woo-quick-view allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Quick View: from n/a through <= 1.1.1. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Marko-m Quick CountAI | 22/1/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Marko-M Quick Count quick-count allows Object Injection.This issue affects Quick Count: from n/a through <= 3.00. | |
| Aplazada | Alta (7.1) | 0.34% | — | Perfectsolution WP Ecommerce QuickpayAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PerfectSolution WP eCommerce Quickpay wp-ecommerce-quickpay allows Reflected XSS.This issue affects WP eCommerce Quickpay: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.35% | — | Fahadmahmood WP Quick ShopAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Quick Shop wp-quick-shop allows Reflected XSS.This issue affects WP Quick Shop: from n/a through <= 1.3.1. | |
| Aplazada | Media (5.4) | 0.35% | — | Arulprasadj WP Quick Post DuplicatorAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through 2.0. | |
| Aplazada | Alta (7.5) | 0.76% | — | Fullworksplugins Quick Paypal PaymentsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Paypal Payments: from n/a through 5.7.25. | |
| Aplazada | Media (6.5) | 0.71% | — | Fullworksplugins Quick Contact FormAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Contact Form : from n/a through 8.0.3.1. | |
| Aplazada | Media (5.3) | 0.66% | — | Fullworksplugins Quick Event ManagerAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Event Manager: from n/a through 9.7.4. | |
| Aplazada | Media (6.1) | 0.27% | — | Quick License ManagerAI | 3/12/2024 | 17/6/2026 | The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, and including, 2.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (4.3) | 0.34% | — | Samsung Quick Share | 3/12/2024 | 17/6/2026 | Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location. | |
| Aplazada | Crítica (9.1) | 0.82% | — | Opensolution Quick.cmsAI | 29/11/2024 | 17/6/2026 | Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictions and download any file if it has the appropriate permissions outside of documentroot configured on the server via the aDirFiles%5B0%5D parameter in the admin.php page.… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Rajesh Thanoch Quick LearnAI | 20/11/2024 | 17/6/2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoch Quick Learn quick-learn allows Object Injection.This issue affects Quick Learn: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.31% | — | Quickheal Antivirus PROAI | 18/11/2024 | 17/6/2026 | Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings. | |
| Aplazada | Alta (8.8) | 0.38% | — | Quickheal Antivirus PROAIQuickheal Total SecurityAI | 18/11/2024 | 17/6/2026 | An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges. | |
| Modificada | Alta (8.8) | 0.92% | 💥 PoC | Antonhoelstad WP Quick Setup | 18/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0. | |
| Analizada | Media (5.9) | 0.39% | — | Google Quick Share | 7/11/2024 | 17/6/2026 | There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is contained in this frame is written to disk in the Downloads… | |
| Aplazada | Media (6.5) | 0.43% | — | ACF Quick Edit FieldsAI | 16/10/2024 | 17/6/2026 | The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above. |