Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

927 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.2%💥 PoCSPX Graphics Controller16/9/202417/6/2026
An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.
AnalizadaAlta (7.5)0.86%—Apollographql Apollo-routerApollographql Apollo Helms-charts RouterApollographql Apollo Router27/8/202417/6/2026
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if _all_ of the following are true: 1. The Apollo…
AnalizadaAlta (7.5)0.99%—Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+127/8/202417/6/2026
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.…
AnalizadaMedia (5.1)0.13%—Intel ARC A GraphicsIntel Iris XE Graphics14/8/202417/6/2026
Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaMedia (5.4)0.14%—Intel Graphics Performance Analyzers14/8/202417/6/2026
Uncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.15%—Intel Integrated Performance Primitives CryptographyIntel Oneapi Base Toolkit14/8/202417/6/2026
Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.5)0.26%—Iqonic Design GraphinaAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Iqonic Design Graphina allows Stored XSS.This issue affects Graphina: from n/a through 1.8.10.
AplazadaMedia (5.3)0.94%💥 PoCGraphql-java Graphql JavaAI30/7/202417/6/2026
GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.
AplazadaCrítica (9.8)0.81%—Asial Jpgraph ProfessionalAI4/7/202417/6/2026
QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.
ModificadaBaja (3.8)0.43%—Aimeos Ai-admin-graphql2/7/202417/6/2026
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and…
AplazadaAlta (7.1)0.44%—Aimeos Ai-admin-graphqlAI2/7/202417/6/2026
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6…
ModificadaAlta (8.8)0.25%—Davekiss Vimeography21/6/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dave Kiss Vimeography: Vimeo Video Gallery WordPress Plugin.This issue affects Vimeography: Vimeo Video Gallery WordPress Plugin: from n/a through 2.4.1.
AplazadaAlta (7.5)0.56%—ClassgraphAI21/6/202417/6/2026
ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.
AplazadaMedia (4.3)0.32%—AI Infographic MakerAI15/6/202417/6/2026
The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action in all versions up to, and including, 4.7.4. This makes it possible for authenticated attackers, with Subscriber-level access and above,…
ModificadaMedia (5.4)0.25%—Themefreesia Pixgraphy8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Freesia Pixgraphy allows Stored XSS.This issue affects Pixgraphy: from n/a through 1.3.8.
ModificadaMedia (5.3)0.45%—Willnorris Open Graph6/6/202417/6/2026
The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.2 via the 'opengraph_default_description' function. This makes it possible for unauthenticated attackers to extract sensitive data including partial content of password-protected blog posts.
AplazadaAlta (7.8)0.34%—Intel ARC GraphicsAIIntel Iris XE GraphicsAI16/5/202417/6/2026
Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.
AnalizadaAlta (7.8)0.18%—Intel Graphics Performance Analyzers Framework16/5/202417/6/2026
Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.19%—Intel Graphics Performance Analyzers16/5/202417/6/2026
Uncontrolled search path in some Intel(R) GPA software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.7)0.20%—Intel Graphics Command Center ServiceAIIntel Graphics Windows DCH DriverAI16/5/202417/6/2026
Uncontrolled search path in Intel(R) Graphics Command Center Service bundled in some Intel(R) Graphics Windows DCH driver software before versions 31.0.101.3790/31.0.101.2114 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.21%—Intel Graphics Performance Analyzers Framework16/5/202417/6/2026
Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.21%—Intel Graphics Performance Analyzers16/5/202417/6/2026
Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.20%—Intel Graphics Performance Analyzers16/5/202417/6/2026
Uncontrolled search path in some Intel(R) GPA software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.21%—Intel Graphics Performance Analyzers16/5/202417/6/2026
Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.20%—Intel Graphics Performance Analyzers Framework16/5/202417/6/2026
Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.