Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.19% | — | Gwycon Quick Code | 12/9/2024 | 17/6/2026 | The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Aplazada | Crítica (9.8) | 0.97% | — | ProductinfoquickAIUeditorAI | 12/8/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file. | |
| Modificada | Media (6.9) | 7.0% | 💥 Exploit | Bylancer Quicklancer | 29/7/2024 | 17/6/2026 | A vulnerability was found in Bylancer Quicklancer 2.4. It has been rated as critical. This issue affects some unknown processing of the file /listing of the component GET Parameter Handler. The manipulation of the argument range2 leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (4.8) | 0.35% | — | Holoborodko WP Quicklatex | 22/7/2024 | 17/6/2026 | The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.3) | 0.55% | — | Addonify Quick View FOR WoocommerceAI | 20/7/2024 | 17/6/2026 | The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.16. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path… | |
| Analizada | Alta (7.1) | 0.43% | — | Holoborodko WP Quicklatex | 13/7/2024 | 17/6/2026 | The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.9) | 0.44% | — | Phil Baylog QuickiebarAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Baylog QuickieBar allows Stored XSS.This issue affects QuickieBar: from n/a through 1.8.4. | |
| Analizada | Media (4) | 0.32% | — | Bellard Quickjs | 14/5/2024 | 17/6/2026 | QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c. | |
| Aplazada | Media (4.3) | 0.34% | — | Quick Featured ImagesAI | 23/4/2024 | 17/6/2026 | The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the set_thumbnail and delete_thumbnail functions in all versions up to, and including, 13.7.0. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Analizada | Baja (3.9) | 0.34% | — | Quickjs Project Quickjs | 23/4/2024 | 17/6/2026 | QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closures. | |
| Analizada | Alta (7.5) | 0.64% | — | Quickjs Project Quickjs | 23/4/2024 | 17/6/2026 | QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval. | |
| Modificada | Media (4.4) | 0.33% | — | Wpclever WPC Smart Quick View FOR Woocommerce | 13/4/2024 | 17/6/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Aplazada | Media (5.4) | 0.20% | — | Quick-plugins Loan Repayment Calculator AND Application FormAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in aerin Loan Repayment Calculator and Application Form.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.4. | |
| Aplazada | Media (5.3) | 0.36% | — | Mark Stockton Quicksand Post Filter Jquery PluginAI | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1. | |
| Analizada | Crítica (9.8) | 0.56% | — | Fmemodules B2B Quick Order Form | 14/3/2024 | 17/6/2026 | SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods. | |
| Modificada | Alta (8.8) | 0.21% | — | Developingtheweb Quicksand Post Filter Jquery | 21/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1. | |
| Modificada | Media (6.5) | 0.21% | — | Intel Quickassist Technology Driver | 14/2/2024 | 17/6/2026 | Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.5) | 0.77% | 💥 PoC | Eyuepcanyilmaz Root Quick Reboot | 5/2/2024 | 17/6/2026 | The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation. | |
| Modificada | Alta (7.8) | 0.24% | — | Innovadeluxe Quick Order | 28/12/2023 | 17/6/2026 | SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file. | |
| Modificada | Media (4.8) | 0.34% | — | Quick-plugins Loan Repayment Calculator AND Application Form | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aerin Loan Repayment Calculator and Application Form allows Stored XSS.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.3. | |
| Modificada | Media (6.1) | 0.47% | — | Crmperks Integration FOR Woocommerce AND Quickbooks | 19/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and QuickBooks.This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.2.3. | |
| Modificada | Media (6.1) | 0.40% | — | Joomboost Easy Quick Contact | 14/12/2023 | 17/6/2026 | A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla. | |
| Modificada | Media (6.1) | 0.40% | — | Plasma-web Quickform | 14/12/2023 | 17/6/2026 | A reflected XSS vulnerability was discovered in the Quickform component for Joomla. | |
| Modificada | Media (4.8) | 0.39% | — | Codez Quick Call Button | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codez Quick Call Button plugin <= 1.2.9 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Intel Quickassist Technology | 14/11/2023 | 17/6/2026 | Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access. |