Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.21% | — | Intel Quickassist Technology LibraryIntel Quickassist Technology | 14/11/2023 | 17/6/2026 | Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Quickassist Technology LibraryIntel Quickassist Technology | 14/11/2023 | 17/6/2026 | Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Quickassist Technology LibraryIntel Quickassist Technology Firmware | 14/11/2023 | 17/6/2026 | Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Baja (2.3) | 0.21% | — | Intel Quickassist Technology LibraryIntel Quickassist Technology Driver FirmwareIntel QAT Driver Firmware | 14/11/2023 | 17/6/2026 | Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.8) | 0.39% | — | Grandplugins WOO Quick View AND BUY NOW | 14/11/2023 | 17/6/2026 | Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in GrandPlugins Direct Checkout – Quick View – Buy Now For WooCommerce plugin <= 1.5.8 versions. | |
| Modificada | Media (5.5) | 0.19% | — | Samsung Quick Share | 7/11/2023 | 17/6/2026 | Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files. | |
| Modificada | Media (5.4) | 0.48% | 💥 PoC | Opensolution Quick CMS | 20/10/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Backend - Dashboard parameter in the Languages Menu component. | |
| Modificada | Alta (8.6) | 0.36% | 💥 PoC | Opensolution Quick CMS | 19/10/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Content - Name parameter in the Pages Menu component. | |
| Modificada | Media (5.4) | 0.64% | 💥 PoC | Opensolution Quick CMS | 19/10/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the SEO - Meta description parameter in the Pages Menu component. | |
| Modificada | Media (5.4) | 0.49% | 💥 PoC | Opensolution Quick CMS | 19/10/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Languages Menu component. | |
| Modificada | Media (5.4) | 0.69% | 💥 PoC | Opensolution Quick CMS | 5/10/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Files - Description parameter in the Pages Menu component. | |
| Modificada | Alta (7.4) | 0.35% | — | Selinc Sel-5030 Acselerator Quickset | 31/8/2023 | 17/6/2026 | An Incomplete Filtering of Special Elements vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated 20230615 for more… | |
| Modificada | Media (6.5) | 0.34% | — | Selinc Sel-5030 Acselerator Quickset | 31/8/2023 | 17/6/2026 | An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix… | |
| Modificada | Media (6.5) | 0.35% | — | Selinc Sel-5030 Acselerator Quickset | 31/8/2023 | 17/6/2026 | An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated… | |
| Modificada | Media (5.7) | 0.43% | — | Selinc Sel-5030 Acselerator Quickset | 31/8/2023 | 17/6/2026 | An Improper Handling of Unicode Encoding vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated 20230615 for more… | |
| Modificada | Media (6.5) | 0.39% | — | Selinc Sel-5030 Acselerator Quickset | 31/8/2023 | 17/6/2026 | An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated… | |
| Modificada | Media (4.8) | 0.37% | — | Anadnet Quick Page/post Redirect Plugin | 8/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anadnet Quick Page/Post Redirect Plugin plugin <= 5.2.3 versions. | |
| Modificada | Crítica (9.8) | 0.50% | — | Bylancer Quickorder | 16/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Bylancer QuickOrder 6.3.7. Affected by this issue is some unknown functionality of the file /blog of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection. The attack may be launched remotely. The identifier… | |
| Modificada | Crítica (9.8) | 0.50% | — | Bylancer Quickqr | 16/7/2023 | 17/6/2026 | A vulnerability classified as critical was found in Bylancer QuickQR 6.3.7. Affected by this vulnerability is an unknown functionality of the file /blog of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection. The attack can be launched remotely. The associated identifier of… | |
| Modificada | Crítica (9.8) | 0.50% | — | Bylancer Quickjob | 16/7/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Bylancer QuickJob 6.1. Affected is an unknown function of the component GET Parameter Handler. The manipulation of the argument keywords/gender leads to sql injection. It is possible to launch the attack remotely. VDB-234234 is the identifier assigned to this… | |
| Modificada | Crítica (9.8) | 0.50% | — | Bylancer Quickvcard | 16/7/2023 | 17/6/2026 | A vulnerability was found in Bylancer QuickVCard 2.1. It has been rated as critical. This issue affects some unknown processing of the file /blog of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection. The attack may be initiated remotely. The identifier VDB-234233 was… | |
| Modificada | Crítica (9.8) | 0.50% | — | Bylancer Quickai Openai | 16/7/2023 | 17/6/2026 | A vulnerability was found in Bylancer QuickAI OpenAI 3.8.1. It has been declared as critical. This vulnerability affects unknown code of the file /blog of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection. The attack can be initiated remotely. The identifier of this… | |
| Modificada | Media (4.8) | 0.37% | — | Wpovernight Download Quick/bulk Order Form FOR Woocommerce | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Overnight Quick/Bulk Order Form for WooCommerce plugin <= 3.5.7 versions. | |
| Modificada | Media (4.3) | 0.79% | — | Webdevocean WP Quick Frontend Editor | 7/6/2023 | 17/6/2026 | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as subscribers, to edit/create any page or… | |
| Modificada | Media (5.4) | 0.49% | — | Webdevocean WP Quick Frontend Editor | 7/6/2023 | 17/6/2026 | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with minimal permissions like subscribers, to inject arbitrary web scripts… |