Show filters
596 Total Results
Displaying 1-10 of 596
Sort by:
Attacker Value
High
CVE-2021-42258
Disclosure Date: October 22, 2021 (last updated February 23, 2025)
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell.
3
Attacker Value
Unknown
CVE-2012-0663 Apple Quicktime Buffer Overflow
Disclosure Date: May 16, 2012 (last updated December 06, 2023)
Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TeXML file.
0
Attacker Value
Unknown
CVE-2024-31858
Disclosure Date: February 12, 2025 (last updated February 27, 2025)
Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2024-31153
Disclosure Date: February 12, 2025 (last updated February 27, 2025)
Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.
0
Attacker Value
Unknown
CVE-2024-29223
Disclosure Date: February 12, 2025 (last updated February 27, 2025)
Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2025-24705
Disclosure Date: January 24, 2025 (last updated February 27, 2025)
Missing Authorization vulnerability in Arshid WooCommerce Quick View allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce Quick View: from n/a through 1.1.1.
0
Attacker Value
Unknown
CVE-2025-23932
Disclosure Date: January 22, 2025 (last updated February 27, 2025)
Deserialization of Untrusted Data vulnerability in NotFound Quick Count allows Object Injection. This issue affects Quick Count: from n/a through 3.00.
0
Attacker Value
Unknown
CVE-2024-56023
Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Perfect Solution WP eCommerce Quickpay allows Reflected XSS.This issue affects WP eCommerce Quickpay: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2024-54344
Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Quick Shop allows Reflected XSS.This issue affects WP Quick Shop: from n/a through 1.3.1.
0
Attacker Value
Unknown
CVE-2023-31214
Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through 2.0.
0