Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 300 respecto a la semana anterior
Críticas / altas1348▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.1) | 0.31% | — | Wpclever WPC Smart Quick ViewAI | 3/10/2026 | 3/10/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.9) | 0.17% | — | Quick.cartAI | 29/9/2026 | 30/9/2026 | Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it… | |
| Pendiente de análisis | Crítica (9.8) | 0.45% | — | QuickjsAI | 24/9/2026 | 29/9/2026 | QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag(). | |
| Pendiente de análisis | Baja (0.6) | 0.10% | — | QT QuickAI | 23/9/2026 | 24/9/2026 | Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path. | |
| Pendiente de análisis | Alta (8.7) | 1.9% | — | Amazon S2n-quicAI | 22/9/2026 | 23/9/2026 | Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only server endpoints specifically configured to send Retry packets are affected. To… | |
| Pendiente de análisis | Alta (8.7) | 0.48% | — | QuickwitAI | 16/9/2026 | 24/9/2026 | Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a malicious queue_url to the create-source API to scan internal networks and fingerprint services based… | |
| Pendiente de análisis | Alta (8.2) | 0.28% | — | Libp2p QuicAILibp2p TLSAI | 15/9/2026 | 30/9/2026 | libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate and delayed the final TLS 1.3 handshake fragment until after the certificate… | |
| Aplazada | Media (5.3) | 0.52% | — | Quic-go Webtransport-goAI | 14/9/2026 | 30/9/2026 | webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, retaining the complete declared capsule body in memory. A malicious peer can send… | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Quick IndexAIJoomlaAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A crafted value can close the intended class attribute and introduce a new attribute.… | |
| Aplazada | Alta (7.2) | 0.19% | — | QuickcalAI | 5/9/2026 | 8/9/2026 | The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Alta (7.1) | 0.25% | — | Fullworksplugins Quick Event ManagerAI | 3/9/2026 | 4/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fullworksplugins Quick Event ManagerAI | 3/9/2026 | 5/9/2026 | Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Holoborodko WP QuicklatexAI | 3/9/2026 | 4/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | |
| Pendiente de análisis | Crítica (9.2) | 0.76% | — | Nginx NJSAINginxAIBellard QuickjsAI | 2/9/2026 | 3/9/2026 | Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method.… | |
| Pendiente de análisis | Alta (8.8) | 0.38% | — | Nginx NJSAIQuickjs QJSAI | 2/9/2026 | 3/9/2026 | Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this… | |
| Analizada | Media (5.3) | 0.32% | — | Quick Tabs Project Quick Tabs | 2/9/2026 | 16/9/2026 | Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1. | |
| Aplazada | Crítica (9.3) | 0.81% | — | Zbtlink L3 V2 8AIZbtlink We826-t2AIZbtlink Zbt-7628AIZbtlink Zbt-zbt7621AI+11 | 27/8/2026 | 24/9/2026 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380,… | |
| Aplazada | Crítica (9.1) | 0.25% | — | Erlang QuicAI | 14/8/2026 | 18/9/2026 | erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so `verify` was… | |
| Aplazada | Media (5.3) | 0.16% | — | Fullworksplugins Quick Paypal PaymentsAI | 12/8/2026 | 26/8/2026 | The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid. | |
| Aplazada | Media (5.1) | 0.41% | — | Opensolution Quick.cmsAI | 29/7/2026 | 30/7/2026 | A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. The vendor states that this administration panel already allows for significant modification… | |
| Aplazada | Media (6.8) | 0.18% | — | Quick CartAI | 28/7/2026 | 30/7/2026 | Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix… | |
| Aplazada | Media (5.1) | 0.57% | — | Opensolution Quick.cmsAI | 28/7/2026 | 30/7/2026 | A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files… | |
| Aplazada | Media (5.1) | 0.53% | — | Opensolution Quick.cmsAI | 28/7/2026 | 30/7/2026 | Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server's… | |
| Aplazada | Alta (7) | 0.57% | — | Opensolution Quick CMSAI | 28/7/2026 | 30/7/2026 | In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can… | |
| Aplazada | Media (6.7) | 0.38% | — | QuickcalAI | 23/7/2026 | 23/7/2026 | Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. |