Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
–

197 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.52%—Quantumcloud Conversational Forms FOR ChatbotAI30/9/202630/9/2026
Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
AnalizadaCrítica (9.8)20%⚠ Explotación activaCheckpoint Multi-domain Security ManagementCheckpoint Quantum Security Management22/9/202623/9/2026
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Pendiente de análisisCrítica (9.8)3.7%—Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI9/9/202610/9/2026
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
AplazadaBaja (2.1)0.39%—Quantumnous New-apiAI31/8/20262/9/2026
A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been…
Pendiente de análisisMedia (4.1)0.10%—HCL Bigfix Quantum Risk AnalyzerAI26/8/202628/8/2026
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.
Pendiente de análisisBaja (3.9)0.09%—HCL Bigfix Quantum Risk AnalyzerAI26/8/202628/8/2026
HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
Pendiente de análisisMedia (4.4)0.07%—HCL Bigfix Quantum Risk AnalyzerAI26/8/202628/8/2026
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
Pendiente de análisisBaja (3.9)0.09%—HCL Bigfix Quantum Risk AnalyzerAI26/8/202628/8/2026
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.
AplazadaMedia (4.9)0.48%—Quantumcloud Slider HeroAI16/8/202620/8/2026
The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data (description, title, btn, btn2, image_link, custom, etc.) is stored safely via $wpdb->update() with %s placeholders in the qchero_save_image…
AnalizadaCrítica (9.3)78%⚠ Explotación activaCheckpoint Multi-domain Security ManagementCheckpoint Quantum Security Management22/7/202610/8/2026
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security…
AplazadaAlta (7.7)0.46%—Filebrowser QuantumAI20/7/202623/7/2026
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent…
AplazadaMedia (5.3)0.47%—Filebrowser QuantumAI20/7/202622/7/2026
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost immediately. When a valid username is provided,…
AplazadaAlta (8.7)0.45%—Filebrowser QuantumAI20/7/202622/7/2026
FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. Versions 1.3.2-stable and 1.4.1-beta fix the issue. No known workarounds are available.
AplazadaCrítica (9.9)0.48%—Quantumcloud Woowbot PRO MAXAI13/7/202613/7/2026
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.
AplazadaCrítica (9.3)0.40%—Quantumcloud Simple Business Directory PROAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4.
AplazadaMedia (6.5)0.22%—Quantumcloud Chatbot FOR Ecommerce WoowbotAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce &#8211; WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce &#8211; WoowBot: from n/a through <= 4.6.1.
AplazadaAlta (7.1)0.25%—Quantumcloud ChatbotAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.
AplazadaAlta (7.1)0.25%—Quantumcloud Simple Link DirectoryAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
AplazadaAlta (7.5)0.43%—Quantumcloud Conversational Forms FOR ChatbotAI17/6/20261/10/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.
AplazadaCrítica (9.3)0.52%—Filebrowser QuantumAI16/6/202617/6/2026
FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go which joins user-controlled fromPath and toPath body fields with the trusted d.share.Path BEFORE the…
AplazadaMedia (5.1)0.24%—Quantumcloud Simple Link DirectoryAI10/6/202623/7/2026
Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.
AplazadaMedia (5.1)0.24%—Quantumcloud Simple Link DirectoryAI10/6/202623/7/2026
Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.
AnalizadaMedia (5.3)0.30%—Openquantumsafe Liboqs29/5/202622/7/2026
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a correctly-sized signature buffer…
AnalizadaMedia (5.3)0.30%—Openquantumsafe Liboqs29/5/202621/7/2026
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a signature buffer shorter than the…
AplazadaBaja (2.9)0.46%—Quantumnous New-apiAI23/5/202623/7/2026
A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The…