Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.2% | 💥 PoC | SPX Graphics Controller | 16/9/2024 | 17/6/2026 | An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function. | |
| Analizada | Alta (7.5) | 0.86% | — | Apollographql Apollo-routerApollographql Apollo Helms-charts RouterApollographql Apollo Router | 27/8/2024 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if _all_ of the following are true: 1. The Apollo… | |
| Analizada | Alta (7.5) | 0.99% | — | Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+1 | 27/8/2024 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.… | |
| Analizada | Media (5.1) | 0.13% | — | Intel ARC A GraphicsIntel Iris XE Graphics | 14/8/2024 | 17/6/2026 | Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Media (5.4) | 0.14% | — | Intel Graphics Performance Analyzers | 14/8/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.15% | — | Intel Integrated Performance Primitives CryptographyIntel Oneapi Base Toolkit | 14/8/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.5) | 0.26% | — | Iqonic Design GraphinaAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Iqonic Design Graphina allows Stored XSS.This issue affects Graphina: from n/a through 1.8.10. | |
| Aplazada | Media (5.3) | 0.94% | 💥 PoC | Graphql-java Graphql JavaAI | 30/7/2024 | 17/6/2026 | GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions. | |
| Aplazada | Crítica (9.8) | 0.81% | — | Asial Jpgraph ProfessionalAI | 4/7/2024 | 17/6/2026 | QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product. | |
| Modificada | Baja (3.8) | 0.43% | — | Aimeos Ai-admin-graphql | 2/7/2024 | 17/6/2026 | aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and… | |
| Aplazada | Alta (7.1) | 0.44% | — | Aimeos Ai-admin-graphqlAI | 2/7/2024 | 17/6/2026 | aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6… | |
| Modificada | Alta (8.8) | 0.25% | — | Davekiss Vimeography | 21/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dave Kiss Vimeography: Vimeo Video Gallery WordPress Plugin.This issue affects Vimeography: Vimeo Video Gallery WordPress Plugin: from n/a through 2.4.1. | |
| Aplazada | Alta (7.5) | 0.56% | — | ClassgraphAI | 21/6/2024 | 17/6/2026 | ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks. | |
| Aplazada | Media (4.3) | 0.32% | — | AI Infographic MakerAI | 15/6/2024 | 17/6/2026 | The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action in all versions up to, and including, 4.7.4. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Modificada | Media (5.4) | 0.25% | — | Themefreesia Pixgraphy | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Freesia Pixgraphy allows Stored XSS.This issue affects Pixgraphy: from n/a through 1.3.8. | |
| Modificada | Media (5.3) | 0.45% | — | Willnorris Open Graph | 6/6/2024 | 17/6/2026 | The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.2 via the 'opengraph_default_description' function. This makes it possible for unauthenticated attackers to extract sensitive data including partial content of password-protected blog posts. | |
| Aplazada | Alta (7.8) | 0.34% | — | Intel ARC GraphicsAIIntel Iris XE GraphicsAI | 16/5/2024 | 17/6/2026 | Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access. | |
| Analizada | Alta (7.8) | 0.18% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.19% | — | Intel Graphics Performance Analyzers | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.7) | 0.20% | — | Intel Graphics Command Center ServiceAIIntel Graphics Windows DCH DriverAI | 16/5/2024 | 17/6/2026 | Uncontrolled search path in Intel(R) Graphics Command Center Service bundled in some Intel(R) Graphics Windows DCH driver software before versions 31.0.101.3790/31.0.101.2114 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.21% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.21% | — | Intel Graphics Performance Analyzers | 16/5/2024 | 17/6/2026 | Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.20% | — | Intel Graphics Performance Analyzers | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.21% | — | Intel Graphics Performance Analyzers | 16/5/2024 | 17/6/2026 | Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.20% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. |