Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

791 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.31%—Wpclever WPC Smart Quick ViewAI3/10/20266/10/2026
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (6.9)0.17%—Quick.cartAI29/9/202630/9/2026
Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it…
Pendiente de análisisCrítica (9.8)0.45%—QuickjsAI24/9/202629/9/2026
QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag().
Pendiente de análisisBaja (0.6)0.10%—QT QuickAI23/9/202624/9/2026
Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.
Pendiente de análisisAlta (8.7)0.48%—QuickwitAI16/9/202624/9/2026
Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a malicious queue_url to the create-source API to scan internal networks and fingerprint services based…
AplazadaAlta (7.5)0.42%—Regularlabs Quick IndexAIJoomlaAI14/9/202616/9/2026
Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A crafted value can close the intended class attribute and introduce a new attribute.…
AplazadaAlta (7.2)0.19%—QuickcalAI5/9/20268/9/2026
The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AplazadaAlta (7.1)0.25%—Fullworksplugins Quick Event ManagerAI3/9/20264/9/2026
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
AplazadaAlta (7.5)0.35%—Fullworksplugins Quick Event ManagerAI3/9/20265/9/2026
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
AplazadaAlta (7.1)0.25%—Holoborodko WP QuicklatexAI3/9/20264/9/2026
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
Pendiente de análisisCrítica (9.2)0.76%—Nginx NJSAINginxAIBellard QuickjsAI2/9/20263/9/2026
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method.…
Pendiente de análisisAlta (8.8)0.38%—Nginx NJSAIQuickjs QJSAI2/9/20263/9/2026
Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this…
AnalizadaMedia (5.3)0.32%—Quick Tabs Project Quick Tabs2/9/202616/9/2026
Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.
AplazadaCrítica (9.3)0.81%—Zbtlink L3 V2 8AIZbtlink We826-t2AIZbtlink Zbt-7628AIZbtlink Zbt-zbt7621AI+1127/8/202624/9/2026
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380,…
AplazadaMedia (5.3)0.16%—Fullworksplugins Quick Paypal PaymentsAI12/8/202626/8/2026
The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid.
AplazadaMedia (5.1)0.41%—Opensolution Quick.cmsAI29/7/202630/7/2026
A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. The vendor states that this administration panel already allows for significant modification…
AplazadaMedia (6.8)0.18%—Quick CartAI28/7/202630/7/2026
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix…
AplazadaMedia (5.1)0.57%—Opensolution Quick.cmsAI28/7/202630/7/2026
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files…
AplazadaMedia (5.1)0.53%—Opensolution Quick.cmsAI28/7/202630/7/2026
Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server's…
AplazadaAlta (7)0.57%—Opensolution Quick CMSAI28/7/202630/7/2026
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can…
AplazadaMedia (6.7)0.38%—QuickcalAI23/7/202623/7/2026
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
AnalizadaCrítica (9)0.57%—Delskayn RquickjsSurrealdb18/7/202613/8/2026
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
AplazadaCrítica (9.8)0.55%—Dbix QuickormAISQL AbstractAI30/6/202630/6/2026
DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its constructor but never quote_char, so SQL::Abstract emits identifiers verbatim. Caller-supplied identifiers (order_by, where-clause column keys,…
AplazadaAlta (7.1)0.25%—Quick Interest SliderAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.
AplazadaAlta (7.5)0.24%—Quick CMSAI15/6/202624/7/2026
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization is performed without proper validation or class restrictions, crafted payloads…