Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

791 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.19%—Gwycon Quick Code12/9/202417/6/2026
The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
AplazadaCrítica (9.8)0.97%—ProductinfoquickAIUeditorAI12/8/202417/6/2026
An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
ModificadaMedia (6.9)7.0%💥 ExploitBylancer Quicklancer29/7/202417/6/2026
A vulnerability was found in Bylancer Quicklancer 2.4. It has been rated as critical. This issue affects some unknown processing of the file /listing of the component GET Parameter Handler. The manipulation of the argument range2 leads to sql injection. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (4.8)0.35%—Holoborodko WP Quicklatex22/7/202417/6/2026
The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaMedia (5.3)0.55%—Addonify Quick View FOR WoocommerceAI20/7/202417/6/2026
The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.16. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path…
AnalizadaAlta (7.1)0.43%—Holoborodko WP Quicklatex13/7/202417/6/2026
The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaMedia (5.9)0.44%—Phil Baylog QuickiebarAI14/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Baylog QuickieBar allows Stored XSS.This issue affects QuickieBar: from n/a through 1.8.4.
AnalizadaMedia (4)0.32%—Bellard Quickjs14/5/202417/6/2026
QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.
AplazadaMedia (4.3)0.34%—Quick Featured ImagesAI23/4/202417/6/2026
The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the set_thumbnail and delete_thumbnail functions in all versions up to, and including, 13.7.0. This makes it possible for authenticated attackers, with contributor-level access and…
AnalizadaBaja (3.9)0.34%—Quickjs Project Quickjs23/4/202417/6/2026
QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closures.
AnalizadaAlta (7.5)0.64%—Quickjs Project Quickjs23/4/202417/6/2026
QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.
ModificadaMedia (4.4)0.33%—Wpclever WPC Smart Quick View FOR Woocommerce13/4/202417/6/2026
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…
AplazadaMedia (5.4)0.20%—Quick-plugins Loan Repayment Calculator AND Application FormAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in aerin Loan Repayment Calculator and Application Form.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.4.
AplazadaMedia (5.3)0.36%—Mark Stockton Quicksand Post Filter Jquery PluginAI11/4/202417/6/2026
Missing Authorization vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1.
AnalizadaCrítica (9.8)0.56%—Fmemodules B2B Quick Order Form14/3/202417/6/2026
SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods.
ModificadaAlta (8.8)0.21%—Developingtheweb Quicksand Post Filter Jquery21/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1.
ModificadaMedia (6.5)0.21%—Intel Quickassist Technology Driver14/2/202417/6/2026
Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.5)0.77%💥 PoCEyuepcanyilmaz Root Quick Reboot5/2/202417/6/2026
The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation.
ModificadaAlta (7.8)0.24%—Innovadeluxe Quick Order28/12/202317/6/2026
SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file.
ModificadaMedia (4.8)0.34%—Quick-plugins Loan Repayment Calculator AND Application Form21/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aerin Loan Repayment Calculator and Application Form allows Stored XSS.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.3.
ModificadaMedia (6.1)0.47%—Crmperks Integration FOR Woocommerce AND Quickbooks19/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and QuickBooks.This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.2.3.
ModificadaMedia (6.1)0.40%—Joomboost Easy Quick Contact14/12/202317/6/2026
A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.
ModificadaMedia (6.1)0.40%—Plasma-web Quickform14/12/202317/6/2026
A reflected XSS vulnerability was discovered in the Quickform component for Joomla.
ModificadaMedia (4.8)0.39%—Codez Quick Call Button22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codez Quick Call Button plugin <= 1.2.9 versions.
ModificadaAlta (8.8)0.31%—Intel Quickassist Technology14/11/202317/6/2026
Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access.
Orbitaley — Vulnerabilidades