Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.52% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 30/9/2026 | 30/9/2026 | Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. | |
| Analizada | Crítica (9.8) | 20% | ⚠ Explotación activa | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/9/2026 | 23/9/2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | |
| Pendiente de análisis | Crítica (9.8) | 3.7% | — | Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI | 9/9/2026 | 10/9/2026 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. | |
| Aplazada | Baja (2.1) | 0.39% | — | Quantumnous New-apiAI | 31/8/2026 | 2/9/2026 | A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been… | |
| Pendiente de análisis | Media (4.1) | 0.10% | — | HCL Bigfix Quantum Risk AnalyzerAI | 26/8/2026 | 28/8/2026 | HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details. | |
| Pendiente de análisis | Baja (3.9) | 0.09% | — | HCL Bigfix Quantum Risk AnalyzerAI | 26/8/2026 | 28/8/2026 | HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. | |
| Pendiente de análisis | Media (4.4) | 0.07% | — | HCL Bigfix Quantum Risk AnalyzerAI | 26/8/2026 | 28/8/2026 | HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary. | |
| Pendiente de análisis | Baja (3.9) | 0.09% | — | HCL Bigfix Quantum Risk AnalyzerAI | 26/8/2026 | 28/8/2026 | HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input. | |
| Aplazada | Media (4.9) | 0.48% | — | Quantumcloud Slider HeroAI | 16/8/2026 | 20/8/2026 | The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data (description, title, btn, btn2, image_link, custom, etc.) is stored safely via $wpdb->update() with %s placeholders in the qchero_save_image… | |
| Analizada | Crítica (9.3) | 78% | ⚠ Explotación activa | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/7/2026 | 10/8/2026 | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security… | |
| Aplazada | Alta (7.7) | 0.46% | — | Filebrowser QuantumAI | 20/7/2026 | 23/7/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent… | |
| Aplazada | Media (5.3) | 0.47% | — | Filebrowser QuantumAI | 20/7/2026 | 22/7/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost immediately. When a valid username is provided,… | |
| Aplazada | Alta (8.7) | 0.45% | — | Filebrowser QuantumAI | 20/7/2026 | 22/7/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. Versions 1.3.2-stable and 1.4.1-beta fix the issue. No known workarounds are available. | |
| Aplazada | Crítica (9.9) | 0.48% | — | Quantumcloud Woowbot PRO MAXAI | 13/7/2026 | 13/7/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Quantumcloud Simple Business Directory PROAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4. | |
| Aplazada | Media (6.5) | 0.22% | — | Quantumcloud Chatbot FOR Ecommerce WoowbotAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce – WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce – WoowBot: from n/a through <= 4.6.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Quantumcloud ChatbotAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7. | |
| Aplazada | Alta (7.1) | 0.25% | — | Quantumcloud Simple Link DirectoryAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 17/6/2026 | 1/10/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8. | |
| Aplazada | Crítica (9.3) | 0.52% | — | Filebrowser QuantumAI | 16/6/2026 | 17/6/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go which joins user-controlled fromPath and toPath body fields with the trusted d.share.Path BEFORE the… | |
| Aplazada | Media (5.1) | 0.24% | — | Quantumcloud Simple Link DirectoryAI | 10/6/2026 | 23/7/2026 | Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser. | |
| Aplazada | Media (5.1) | 0.24% | — | Quantumcloud Simple Link DirectoryAI | 10/6/2026 | 23/7/2026 | Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor. | |
| Analizada | Media (5.3) | 0.30% | — | Openquantumsafe Liboqs | 29/5/2026 | 22/7/2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a correctly-sized signature buffer… | |
| Analizada | Media (5.3) | 0.30% | — | Openquantumsafe Liboqs | 29/5/2026 | 21/7/2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a signature buffer shorter than the… | |
| Aplazada | Baja (2.9) | 0.46% | — | Quantumnous New-apiAI | 23/5/2026 | 23/7/2026 | A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The… |