Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

927 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.81%—Graphviz2/2/202417/6/2026
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.
ModificadaMedia (6.1)0.39%—Apollographql Apollo Client30/1/202417/6/2026
apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this vulnerability, an attacker would need to either inject malicious input (e.g. by redirecting a user to a…
ModificadaMedia (5.3)0.42%—Silverstripe Graphql23/1/202417/6/2026
The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is greater than the number of records per page.…
ModificadaMedia (5.3)0.72%—Wpengine Wpgraphql16/1/202417/6/2026
The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.
ModificadaAlta (7.3)0.48%—SAP Graphical User Interface12/12/202317/6/2026
SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to create Layout…
ModificadaMedia (5.3)2.2%—Microsoft Graph5/12/202317/6/2026
microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at `vendor/microsoft/microsoft-graph-core/tests/GetPhpInfo.php`. The phpInfo…
ModificadaMedia (5.3)2.2%—Microsoft Graph5/12/202317/6/2026
msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php. The phpInfo function…
ModificadaAlta (7.5)0.98%—Cryptography.io Cryptography29/11/202317/6/2026
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for…
AnalizadaAlta (7.5)78%⚠ Explotación activa💥 ExploitOwncloud Graph API21/11/202317/6/2026
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the…
ModificadaCrítica (9.8)1.1%—Redislabs Redisgraph16/11/202317/6/2026
An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsDeleted.
ModificadaAlta (7.3)0.20%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
Unquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.22%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.22%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.17%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.21%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
Out-of-bounds write in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.18%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows Drviers before version 31.0.101.4255 may allow authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.21%—Intel Graphics Driver14/11/202317/6/2026
NULL pointer dereference in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (6.5)0.45%—Wpengine Wpgraphql13/11/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.
ModificadaAlta (8.8)1.0%—Redislabs Redisgraph6/11/202317/6/2026
Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.
ModificadaAlta (8.8)1.1%—Sourcegraph Cody31/10/202317/6/2026
Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 are vulnerable to Remote Code Execution under certain conditions. An attacker in control of a malicious repository could modify the Cody configuration file `.vscode/cody.json` and overwrite Cody…
ModificadaAlta (7.8)0.26%—Ashlar Graphite26/10/202317/6/2026
In Ashlar-Vellum Graphite v13.0.48, the affected application lacks proper validation of user-supplied data when parsing VC6 files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
AnalizadaAlta (7.8)0.20%—Ashlar CobaltAshlar GraphiteAshlar XenonAshlar Argon+126/10/202317/6/2026
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v12 SP0 Build (1204.77), the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of…
ModificadaAlta (8.8)0.28%—Underdock Open Graph Metabox25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Niels van Renselaar Open Graph Metabox plugin <= 1.4.4 versions.
ModificadaAlta (7.5)0.73%—Apollographql Apollo RouterApollographql Apollo Helms-charts Router18/10/202317/6/2026
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send…
ModificadaMedia (4.8)0.32%—Alexmacarthur Complete Open Graph17/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex MacArthur Complete Open Graph plugin <= 3.4.5 versions.
Orbitaley — Vulnerabilidades