Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
844 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.60% | 💥 PoC | Quic-goAI | 2/12/2024 | 17/6/2026 | quic-go is an implementation of the QUIC protocol in Go. An off-path attacker can inject an ICMP Packet Too Large packet. Since affected quic-go versions used IP_PMTUDISC_DO, the kernel would then return a "message too large" error on sendmsg, i.e. when quic-go attempts to send a packet that exceeds the MTU claimed in… | |
| Aplazada | Crítica (9.1) | 0.82% | — | Opensolution Quick.cmsAI | 29/11/2024 | 17/6/2026 | Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictions and download any file if it has the appropriate permissions outside of documentroot configured on the server via the aDirFiles%5B0%5D parameter in the admin.php page.… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Rajesh Thanoch Quick LearnAI | 20/11/2024 | 17/6/2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoch Quick Learn quick-learn allows Object Injection.This issue affects Quick Learn: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.31% | — | Quickheal Antivirus PROAI | 18/11/2024 | 17/6/2026 | Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings. | |
| Aplazada | Alta (8.8) | 0.38% | — | Quickheal Antivirus PROAIQuickheal Total SecurityAI | 18/11/2024 | 17/6/2026 | An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges. | |
| Modificada | Alta (8.8) | 0.92% | 💥 PoC | Antonhoelstad WP Quick Setup | 18/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0. | |
| Analizada | Media (5.9) | 0.39% | — | Google Quick Share | 7/11/2024 | 17/6/2026 | There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is contained in this frame is written to disk in the Downloads… | |
| Aplazada | Media (6.5) | 0.43% | — | ACF Quick Edit FieldsAI | 16/10/2024 | 17/6/2026 | The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above. | |
| Analizada | Alta (7.5) | 0.58% | — | Dena Quicly | 11/10/2024 | 17/6/2026 | Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process using quicly. The vulnerability is addressed with commit 2a95896104901589c495bc41460262e64ffcad5c. | |
| Analizada | Media (6.1) | 0.19% | — | Gwycon Quick Code | 12/9/2024 | 17/6/2026 | The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Aplazada | Crítica (9.8) | 0.97% | — | ProductinfoquickAIUeditorAI | 12/8/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file. | |
| Modificada | Media (6.9) | 7.0% | 💥 Exploit | Bylancer Quicklancer | 29/7/2024 | 17/6/2026 | A vulnerability was found in Bylancer Quicklancer 2.4. It has been rated as critical. This issue affects some unknown processing of the file /listing of the component GET Parameter Handler. The manipulation of the argument range2 leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (4.8) | 0.35% | — | Holoborodko WP Quicklatex | 22/7/2024 | 17/6/2026 | The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.3) | 0.55% | — | Addonify Quick View FOR WoocommerceAI | 20/7/2024 | 17/6/2026 | The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.16. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path… | |
| Analizada | Alta (7.1) | 0.43% | — | Holoborodko WP Quicklatex | 13/7/2024 | 17/6/2026 | The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.9) | 0.44% | — | Phil Baylog QuickiebarAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Baylog QuickieBar allows Stored XSS.This issue affects QuickieBar: from n/a through 1.8.4. | |
| Analizada | Media (4) | 0.32% | — | Bellard Quickjs | 14/5/2024 | 17/6/2026 | QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c. | |
| Aplazada | Media (4.3) | 0.34% | — | Quick Featured ImagesAI | 23/4/2024 | 17/6/2026 | The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the set_thumbnail and delete_thumbnail functions in all versions up to, and including, 13.7.0. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Analizada | Baja (3.9) | 0.34% | — | Quickjs Project Quickjs | 23/4/2024 | 17/6/2026 | QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closures. | |
| Analizada | Alta (7.5) | 0.64% | — | Quickjs Project Quickjs | 23/4/2024 | 17/6/2026 | QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval. | |
| Modificada | Media (4.4) | 0.33% | — | Wpclever WPC Smart Quick View FOR Woocommerce | 13/4/2024 | 17/6/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Aplazada | Media (5.4) | 0.20% | — | Quick-plugins Loan Repayment Calculator AND Application FormAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in aerin Loan Repayment Calculator and Application Form.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.4. | |
| Aplazada | Media (5.3) | 0.36% | — | Mark Stockton Quicksand Post Filter Jquery PluginAI | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1. | |
| Aplazada | Alta (7.5) | 1.1% | — | Quic-goAI | 4/4/2024 | 17/6/2026 | quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run out of memory sending a large number of `NEW_CONNECTION_ID` frames that retire old connection IDs. The receiver is supposed to respond to each retirement frame with a `RETIRE_CONNECTION_ID` frame.… | |
| Aplazada | Media (5.3) | 0.43% | — | Quicoto Thumbs RatingAI | 31/3/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.1.0. |