Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

927 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)0.24%—Paragraphs Table Project Paragraphs Table9/1/202521/7/2026
Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.
AplazadaBaja (3.7)0.38%—DjangoAISqlalchemyAIPydanticAIStrawberry GraphqlAI9/1/202517/6/2026
Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability occurs when multiple GraphQL types are…
AplazadaMedia (6.4)0.34%—Graphpaperpress Sell MediaAI7/1/202517/6/2026
The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_form_gutenberg' shortcode in all versions up to, and including, 2.5.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaAlta (7.8)0.29%—Ashlar Graphite30/12/202417/6/2026
Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaAlta (7.8)0.29%—Ashlar Graphite30/12/202417/6/2026
Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaCrítica (9.8)73%💥 ExploitApache Hugegraph24/12/202417/6/2026
Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.
AplazadaMedia (6.5)0.45%—Nextgeography NG AnalyserAI17/12/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse. This issue affects NG Analyser: before 2.2.711.
AplazadaMedia (5.3)0.58%—Davekiss VimeographyAI16/12/202417/6/2026
Generation of Error Message Containing Sensitive Information vulnerability in videogallery Vimeography vimeography allows Retrieve Embedded Sensitive Data.This issue affects Vimeography: from n/a through <= 2.4.4.
AplazadaMedia (5.3)0.53%—Graphics ColornamesAI13/12/202417/6/2026
An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that can lead to HTML injection by an attacker who can create a file in the current working directory.
AplazadaMedia (6.8)0.18%—Altair Graphql ClientAI9/12/202417/6/2026
Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle to intercept all requests. Any Altair users on untrusted networks (eg. public wifi, malicious DNS servers) may have all GraphQL request and…
AplazadaMedia (6.5)0.29%—Pixobe CartographyAI30/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixobe Pixobe Cartography pixobe-cartography allows DOM-Based XSS.This issue affects Pixobe Cartography: from n/a through <= 1.0.1.
AplazadaMedia (6.5)0.24%—Martythornley Photographer ConnectionsAI18/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MartyThornley Photographer Connections photographer-connections allows Stored XSS.This issue affects Photographer Connections: from n/a through <= 1.3.1.
AplazadaMedia (6.9)0.17%—Intel Graphics DriversAI13/11/202417/6/2026
Out-of-bounds write in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.16%—Intel Graphics DriverAI13/11/202417/6/2026
Uncontrolled search path in the Intel(R) Graphics Driver installers for versions 15.40 and 15.45 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.9)0.18%—Intel Graphics DriversAI13/11/202417/6/2026
Improper buffer restrictions in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (5.4)0.18%—Intel Graphics Offline Compiler FOR OpenclAIIntel Graphics DriverAI13/11/202417/6/2026
Uncontrolled search path in some Intel(R) Graphics Offline Compiler for OpenCL(TM) Code software for Windows before version 2024.1.0.142, graphics driver 31.0.101.5445 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.9)0.18%—Intel Graphics DriversAI13/11/202417/6/2026
Untrusted pointer dereference in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.22%—Intel ARC PRO GraphicsAI13/11/202417/6/2026
Improper access control for some Intel(R) Arc(TM) Pro Graphics for Windows drivers before version 31.0.101.5319 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
AplazadaMedia (4.8)0.18%—Intel Graphics SoftwareAI13/11/202417/6/2026
Improper buffer restrictions in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.5)0.36%—Aimeos Graphql APIAI24/10/202417/6/2026
Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue.
AplazadaAlta (7.5)0.58%—Async-graphqlAI3/10/202417/6/2026
async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion, and User Experience Degradation. This vulnerability is fixed in 7.0.10.
AplazadaMedia (5.3)0.43%—Nippon Telegraph AND Telephone East Corporation Home GatewayAINippon Telegraph AND Telephone East Corporation Hikari DenwaAI26/9/202417/6/2026
Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via…
AnalizadaMedia (5.4)0.32%—Graphicsly25/9/202417/6/2026
The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping.…
AnalizadaCrítica (9.8)1.2%—Vesoft Nebulagraph Database22/9/202417/6/2026
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.
AnalizadaCrítica (9.8)0.58%—Vesoft Nebulagraph Database22/9/202417/6/2026
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.