Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.31% | — | Wpclever WPC Smart Quick ViewAI | 3/10/2026 | 6/10/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.9) | 0.17% | — | Quick.cartAI | 29/9/2026 | 30/9/2026 | Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it… | |
| Pendiente de análisis | Crítica (9.8) | 0.45% | — | QuickjsAI | 24/9/2026 | 29/9/2026 | QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag(). | |
| Pendiente de análisis | Baja (0.6) | 0.10% | — | QT QuickAI | 23/9/2026 | 24/9/2026 | Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path. | |
| Pendiente de análisis | Alta (8.7) | 0.48% | — | QuickwitAI | 16/9/2026 | 24/9/2026 | Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a malicious queue_url to the create-source API to scan internal networks and fingerprint services based… | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Quick IndexAIJoomlaAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A crafted value can close the intended class attribute and introduce a new attribute.… | |
| Aplazada | Alta (7.2) | 0.19% | — | QuickcalAI | 5/9/2026 | 8/9/2026 | The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Alta (7.1) | 0.25% | — | Fullworksplugins Quick Event ManagerAI | 3/9/2026 | 4/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fullworksplugins Quick Event ManagerAI | 3/9/2026 | 5/9/2026 | Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Holoborodko WP QuicklatexAI | 3/9/2026 | 4/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | |
| Pendiente de análisis | Crítica (9.2) | 0.76% | — | Nginx NJSAINginxAIBellard QuickjsAI | 2/9/2026 | 3/9/2026 | Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method.… | |
| Pendiente de análisis | Alta (8.8) | 0.38% | — | Nginx NJSAIQuickjs QJSAI | 2/9/2026 | 3/9/2026 | Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this… | |
| Analizada | Media (5.3) | 0.32% | — | Quick Tabs Project Quick Tabs | 2/9/2026 | 16/9/2026 | Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1. | |
| Aplazada | Crítica (9.3) | 0.81% | — | Zbtlink L3 V2 8AIZbtlink We826-t2AIZbtlink Zbt-7628AIZbtlink Zbt-zbt7621AI+11 | 27/8/2026 | 24/9/2026 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380,… | |
| Aplazada | Media (5.3) | 0.16% | — | Fullworksplugins Quick Paypal PaymentsAI | 12/8/2026 | 26/8/2026 | The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid. | |
| Aplazada | Media (5.1) | 0.41% | — | Opensolution Quick.cmsAI | 29/7/2026 | 30/7/2026 | A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. The vendor states that this administration panel already allows for significant modification… | |
| Aplazada | Media (6.8) | 0.18% | — | Quick CartAI | 28/7/2026 | 30/7/2026 | Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix… | |
| Aplazada | Media (5.1) | 0.57% | — | Opensolution Quick.cmsAI | 28/7/2026 | 30/7/2026 | A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files… | |
| Aplazada | Media (5.1) | 0.53% | — | Opensolution Quick.cmsAI | 28/7/2026 | 30/7/2026 | Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server's… | |
| Aplazada | Alta (7) | 0.57% | — | Opensolution Quick CMSAI | 28/7/2026 | 30/7/2026 | In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can… | |
| Aplazada | Media (6.7) | 0.38% | — | QuickcalAI | 23/7/2026 | 23/7/2026 | Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. | |
| Analizada | Crítica (9) | 0.57% | — | Delskayn RquickjsSurrealdb | 18/7/2026 | 13/8/2026 | SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Dbix QuickormAISQL AbstractAI | 30/6/2026 | 30/6/2026 | DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its constructor but never quote_char, so SQL::Abstract emits identifiers verbatim. Caller-supplied identifiers (order_by, where-clause column keys,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Quick Interest SliderAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions. | |
| Aplazada | Alta (7.5) | 0.24% | — | Quick CMSAI | 15/6/2026 | 24/7/2026 | Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization is performed without proper validation or class restrictions, crafted payloads… |