Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.24% | — | Paragraphs Table Project Paragraphs Table | 9/1/2025 | 21/7/2026 | Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2. | |
| Aplazada | Baja (3.7) | 0.38% | — | DjangoAISqlalchemyAIPydanticAIStrawberry GraphqlAI | 9/1/2025 | 17/6/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability occurs when multiple GraphQL types are… | |
| Aplazada | Media (6.4) | 0.34% | — | Graphpaperpress Sell MediaAI | 7/1/2025 | 17/6/2026 | The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_form_gutenberg' shortcode in all versions up to, and including, 2.5.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (7.8) | 0.29% | — | Ashlar Graphite | 30/12/2024 | 17/6/2026 | Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.29% | — | Ashlar Graphite | 30/12/2024 | 17/6/2026 | Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Crítica (9.8) | 73% | 💥 Exploit | Apache Hugegraph | 24/12/2024 | 17/6/2026 | Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue. | |
| Aplazada | Media (6.5) | 0.45% | — | Nextgeography NG AnalyserAI | 17/12/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse. This issue affects NG Analyser: before 2.2.711. | |
| Aplazada | Media (5.3) | 0.58% | — | Davekiss VimeographyAI | 16/12/2024 | 17/6/2026 | Generation of Error Message Containing Sensitive Information vulnerability in videogallery Vimeography vimeography allows Retrieve Embedded Sensitive Data.This issue affects Vimeography: from n/a through <= 2.4.4. | |
| Aplazada | Media (5.3) | 0.53% | — | Graphics ColornamesAI | 13/12/2024 | 17/6/2026 | An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that can lead to HTML injection by an attacker who can create a file in the current working directory. | |
| Aplazada | Media (6.8) | 0.18% | — | Altair Graphql ClientAI | 9/12/2024 | 17/6/2026 | Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle to intercept all requests. Any Altair users on untrusted networks (eg. public wifi, malicious DNS servers) may have all GraphQL request and… | |
| Aplazada | Media (6.5) | 0.29% | — | Pixobe CartographyAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixobe Pixobe Cartography pixobe-cartography allows DOM-Based XSS.This issue affects Pixobe Cartography: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.24% | — | Martythornley Photographer ConnectionsAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MartyThornley Photographer Connections photographer-connections allows Stored XSS.This issue affects Photographer Connections: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.9) | 0.17% | — | Intel Graphics DriversAI | 13/11/2024 | 17/6/2026 | Out-of-bounds write in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.16% | — | Intel Graphics DriverAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path in the Intel(R) Graphics Driver installers for versions 15.40 and 15.45 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.9) | 0.18% | — | Intel Graphics DriversAI | 13/11/2024 | 17/6/2026 | Improper buffer restrictions in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (5.4) | 0.18% | — | Intel Graphics Offline Compiler FOR OpenclAIIntel Graphics DriverAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Graphics Offline Compiler for OpenCL(TM) Code software for Windows before version 2024.1.0.142, graphics driver 31.0.101.5445 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.9) | 0.18% | — | Intel Graphics DriversAI | 13/11/2024 | 17/6/2026 | Untrusted pointer dereference in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.22% | — | Intel ARC PRO GraphicsAI | 13/11/2024 | 17/6/2026 | Improper access control for some Intel(R) Arc(TM) Pro Graphics for Windows drivers before version 31.0.101.5319 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Aplazada | Media (4.8) | 0.18% | — | Intel Graphics SoftwareAI | 13/11/2024 | 17/6/2026 | Improper buffer restrictions in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.5) | 0.36% | — | Aimeos Graphql APIAI | 24/10/2024 | 17/6/2026 | Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue. | |
| Aplazada | Alta (7.5) | 0.58% | — | Async-graphqlAI | 3/10/2024 | 17/6/2026 | async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion, and User Experience Degradation. This vulnerability is fixed in 7.0.10. | |
| Aplazada | Media (5.3) | 0.43% | — | Nippon Telegraph AND Telephone East Corporation Home GatewayAINippon Telegraph AND Telephone East Corporation Hikari DenwaAI | 26/9/2024 | 17/6/2026 | Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via… | |
| Analizada | Media (5.4) | 0.32% | — | Graphicsly | 25/9/2024 | 17/6/2026 | The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping.… | |
| Analizada | Crítica (9.8) | 1.2% | — | Vesoft Nebulagraph Database | 22/9/2024 | 17/6/2026 | An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection. | |
| Analizada | Crítica (9.8) | 0.58% | — | Vesoft Nebulagraph Database | 22/9/2024 | 17/6/2026 | An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication. |