Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
844 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.21% | — | Crmperks Integration FOR Woocommerce AND QuickbooksAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for WooCommerce and QuickBooks wp-woocommerce-quickbooks allows Cross Site Request Forgery.This issue affects Integration for WooCommerce and QuickBooks: from n/a through <= 1.3.1. | |
| Aplazada | Alta (7.1) | 0.42% | — | Myworks WOO Sync FOR Quickbooks OnlineAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyWorks MyWorks WooCommerce Sync for QuickBooks Online myworks-woo-sync-for-quickbooks-online allows Reflected XSS.This issue affects MyWorks WooCommerce Sync for QuickBooks Online: from n/a through <= 2.9.1. | |
| Aplazada | Alta (8.5) | 0.45% | — | Randyjensen RJ QuickchartsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in randyjensen RJ Quickcharts rj-quickcharts allows SQL Injection.This issue affects RJ Quickcharts: from n/a through <= 0.6.1. | |
| Aplazada | Alta (7.1) | 0.29% | — | Name.ly Quick LocalizationAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Name.ly Quick Localization quick-localization allows Reflected XSS.This issue affects Quick Localization: from n/a through <= 0.1.0. | |
| Aplazada | Media (5.3) | 0.58% | — | Netty Quic CodecAI | 31/3/2025 | 17/6/2026 | Netty QUIC codec is a QUIC codec for netty which makes use of quiche. An issue was discovered in the codec. A hash collision vulnerability (in the hash map used to manage connections) allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding… | |
| Aplazada | Media (6.5) | 0.22% | — | Graham Quick Interest SliderAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Graham Quick Interest Slider quick-interest-slider allows DOM-Based XSS.This issue affects Quick Interest Slider: from n/a through <= 3.1.5. | |
| Aplazada | Media (4.3) | 0.16% | — | Xiaomi Quick APP FrameworkAI | 27/3/2025 | 17/6/2026 | An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is caused by improper input validation and can be exploited by attackers tointent redriction. | |
| Analizada | Media (5.3) | 0.70% | — | Quickjs-ng Quickjs | 21/3/2025 | 17/6/2026 | A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulnerability is the function JS_GetRuntime of the file quickjs.c of the component qjs. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. Upgrading to version… | |
| Aplazada | Media (5.3) | 0.30% | — | Sendquick EnteraAI | 14/3/2025 | 17/6/2026 | SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter. | |
| Aplazada | Media (6.5) | 0.28% | — | Randyjensen Rj-quickchartsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in randyjensen RJ Quickcharts rj-quickcharts allows Stored XSS.This issue affects RJ Quickcharts: from n/a through <= 0.6.1. | |
| Aplazada | Media (5.3) | 0.68% | — | Litespeedtech LsquicAI | 20/2/2025 | 17/6/2026 | A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.0 allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This is caused by XXH32 usage. | |
| Aplazada | Media (5.3) | 0.55% | — | Privateoctopus PicoquicAI | 20/2/2025 | 17/6/2026 | The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function, allowing remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). | |
| Analizada | Alta (7.3) | 0.24% | — | Intel Quickassist Technology | 12/2/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.1) | 0.21% | — | Intel Quickassist Technology | 12/2/2025 | 17/6/2026 | Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Media (5.4) | 0.20% | — | Intel Quickassist Technology | 12/2/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.3) | 0.48% | — | Arshid Woo-quick-viewAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Arshid WooCommerce Quick View woo-quick-view allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Quick View: from n/a through <= 1.1.1. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Marko-m Quick CountAI | 22/1/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Marko-M Quick Count quick-count allows Object Injection.This issue affects Quick Count: from n/a through <= 3.00. | |
| Aplazada | Alta (7.1) | 0.34% | — | Perfectsolution WP Ecommerce QuickpayAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PerfectSolution WP eCommerce Quickpay wp-ecommerce-quickpay allows Reflected XSS.This issue affects WP eCommerce Quickpay: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.35% | — | Fahadmahmood WP Quick ShopAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Quick Shop wp-quick-shop allows Reflected XSS.This issue affects WP Quick Shop: from n/a through <= 1.3.1. | |
| Aplazada | Media (5.4) | 0.35% | — | Arulprasadj WP Quick Post DuplicatorAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through 2.0. | |
| Aplazada | Alta (7.5) | 0.76% | — | Fullworksplugins Quick Paypal PaymentsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Paypal Payments: from n/a through 5.7.25. | |
| Aplazada | Media (6.5) | 0.71% | — | Fullworksplugins Quick Contact FormAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Contact Form : from n/a through 8.0.3.1. | |
| Aplazada | Media (5.3) | 0.66% | — | Fullworksplugins Quick Event ManagerAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Event Manager: from n/a through 9.7.4. | |
| Aplazada | Media (6.1) | 0.27% | — | Quick License ManagerAI | 3/12/2024 | 17/6/2026 | The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, and including, 2.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (4.3) | 0.34% | — | Samsung Quick Share | 3/12/2024 | 17/6/2026 | Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location. |