Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.84% | — | QuinnAI | 23/7/2026 | 30/7/2026 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that… | |
| Aplazada | Alta (8.7) | 0.89% | — | QuinnAI | 10/3/2026 | 25/8/2026 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In… | |
| Aplazada | Media (6.5) | 0.39% | — | Figoliquinn Mobile KioskAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in figoliquinn Mobile Kiosk mobile-kiosk allows Stored XSS.This issue affects Mobile Kiosk: from n/a through <= 1.3.0. | |
| Analizada | Alta (7.5) | 0.57% | — | Quinn Project Quinn | 2/9/2024 | 17/6/2026 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is possible for a server to `accept()`, `retry()`, `refuse()`, or `ignore()` an `Incoming` connection. However, calling `retry()` on an unvalidated connection exposes the server to a likely panic in… | |
| Modificada | Alta (7.5) | 0.94% | — | Quinn Project Quinn | 21/9/2023 | 17/6/2026 | quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QUIC frames in a QUIC packet could result in a panic. The problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. | |
| Modificada | Alta (7.5) | 1.3% | — | Quinn Project Quinn | 5/3/2021 | 17/6/2026 | An issue was discovered in the quinn crate before 0.7.0 for Rust. It may have invalid memory access for certain versions of the standard library because it relies on a direct cast of std::net::SocketAddrV4 and std::net::SocketAddrV6 data structures. | |
| Modificada | Alta (9.3) | 5.8% | — | Quinnware Quintessential Player | 4/12/2006 | 16/6/2026 | Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) M3u or (2) M3u-8 file; or a (3) crafted PLS file with a long value in the (a) NumberofEntries, (b) Length (aka Length1), (c) Filename (aka… | |
| Modificada | Media (4.6) | 0.46% | — | Wquinn Quotaadvisor | 19/12/2000 | 23/9/2026 | WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions. | |
| Modificada | Baja (2.1) | 0.37% | — | Wquinn Diskadvisor | 19/12/2000 | 23/9/2026 | WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares. |