Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.81% | — | Graphviz | 2/2/2024 | 17/6/2026 | Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root. | |
| Modificada | Media (6.1) | 0.39% | — | Apollographql Apollo Client | 30/1/2024 | 17/6/2026 | apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this vulnerability, an attacker would need to either inject malicious input (e.g. by redirecting a user to a… | |
| Modificada | Media (5.3) | 0.42% | — | Silverstripe Graphql | 23/1/2024 | 17/6/2026 | The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is greater than the number of records per page.… | |
| Modificada | Media (5.3) | 0.72% | — | Wpengine Wpgraphql | 16/1/2024 | 17/6/2026 | The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL. | |
| Modificada | Alta (7.3) | 0.48% | — | SAP Graphical User Interface | 12/12/2023 | 17/6/2026 | SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to create Layout… | |
| Modificada | Media (5.3) | 2.2% | — | Microsoft Graph | 5/12/2023 | 17/6/2026 | microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at `vendor/microsoft/microsoft-graph-core/tests/GetPhpInfo.php`. The phpInfo… | |
| Modificada | Media (5.3) | 2.2% | — | Microsoft Graph | 5/12/2023 | 17/6/2026 | msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php. The phpInfo function… | |
| Modificada | Alta (7.5) | 0.98% | — | Cryptography.io Cryptography | 29/11/2023 | 17/6/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for… | |
| Analizada | Alta (7.5) | 78% | ⚠ Explotación activa💥 Exploit | Owncloud Graph API | 21/11/2023 | 17/6/2026 | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the… | |
| Modificada | Crítica (9.8) | 1.1% | — | Redislabs Redisgraph | 16/11/2023 | 17/6/2026 | An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsDeleted. | |
| Modificada | Alta (7.3) | 0.20% | — | Intel Iris XE GraphicsIntel ARC A Graphics | 14/11/2023 | 17/6/2026 | Unquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Iris XE GraphicsIntel ARC A Graphics | 14/11/2023 | 17/6/2026 | Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.22% | — | Intel Iris XE GraphicsIntel ARC A Graphics | 14/11/2023 | 17/6/2026 | Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Iris XE GraphicsIntel ARC A Graphics | 14/11/2023 | 17/6/2026 | Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.21% | — | Intel Iris XE GraphicsIntel ARC A Graphics | 14/11/2023 | 17/6/2026 | Out-of-bounds write in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Iris XE GraphicsIntel ARC A Graphics | 14/11/2023 | 17/6/2026 | NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows Drviers before version 31.0.101.4255 may allow authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.21% | — | Intel Graphics Driver | 14/11/2023 | 17/6/2026 | NULL pointer dereference in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (6.5) | 0.45% | — | Wpengine Wpgraphql | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5. | |
| Modificada | Alta (8.8) | 1.0% | — | Redislabs Redisgraph | 6/11/2023 | 17/6/2026 | Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication. | |
| Modificada | Alta (8.8) | 1.1% | — | Sourcegraph Cody | 31/10/2023 | 17/6/2026 | Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 are vulnerable to Remote Code Execution under certain conditions. An attacker in control of a malicious repository could modify the Cody configuration file `.vscode/cody.json` and overwrite Cody… | |
| Modificada | Alta (7.8) | 0.26% | — | Ashlar Graphite | 26/10/2023 | 17/6/2026 | In Ashlar-Vellum Graphite v13.0.48, the affected application lacks proper validation of user-supplied data when parsing VC6 files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.20% | — | Ashlar CobaltAshlar GraphiteAshlar XenonAshlar Argon+1 | 26/10/2023 | 17/6/2026 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v12 SP0 Build (1204.77), the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of… | |
| Modificada | Alta (8.8) | 0.28% | — | Underdock Open Graph Metabox | 25/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Niels van Renselaar Open Graph Metabox plugin <= 1.4.4 versions. | |
| Modificada | Alta (7.5) | 0.73% | — | Apollographql Apollo RouterApollographql Apollo Helms-charts Router | 18/10/2023 | 17/6/2026 | The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send… | |
| Modificada | Media (4.8) | 0.32% | — | Alexmacarthur Complete Open Graph | 17/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex MacArthur Complete Open Graph plugin <= 3.4.5 versions. |