Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Schneider-electric Interactive Graphical Scada System | 30/1/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to… | |
| Modificada | Crítica (9.8) | 1.1% | — | Schneider-electric Interactive Graphical Scada System | 30/1/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe… | |
| Modificada | Media (5.4) | 0.79% | — | Graphite Project Graphite | 27/12/2022 | 17/6/2026 | A vulnerability was found in Graphite Web. It has been classified as problematic. Affected is an unknown function of the component Absolute Time Range Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (5.4) | 0.76% | — | Graphite Project Graphite | 27/12/2022 | 17/6/2026 | A vulnerability was found in Graphite Web and classified as problematic. This issue affects some unknown processing of the component Template Name Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the… | |
| Modificada | Media (5.4) | 0.79% | — | Graphite Project Graphite | 27/12/2022 | 17/6/2026 | A vulnerability has been found in Graphite Web and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the… | |
| Modificada | Crítica (9.8) | 21% | — | Themographics Listingo | 12/12/2022 | 17/6/2026 | The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE | |
| Modificada | Alta (8.8) | 0.85% | — | Hasura Graphql Engine | 8/12/2022 | 17/6/2026 | Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.) | |
| Modificada | Alta (7.2) | 1.8% | — | Sourcegraph | 22/11/2022 | 17/6/2026 | sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0. | |
| Modificada | Alta (7.8) | 2.8% | — | Sourcegraph | 22/11/2022 | 17/6/2026 | Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. This vulnerability was caused by a lack of input validation on the host parameter of the `/list-gitolite` endpoint. It was possible to send… | |
| Modificada | Media (5.3) | 1.4% | 💥 PoC | Ibexa Ezplatform-graphql | 10/11/2022 | 17/6/2026 | ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically… | |
| Modificada | Media (6.1) | 0.63% | — | Jgraph Mxgraph | 12/10/2022 | 9/7/2026 | mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function. | |
| Modificada | Alta (7.8) | 0.46% | — | GraphicsmagickDebian Linux | 28/9/2022 | 17/6/2026 | In GraphicsMagick, a heap buffer overflow was found when parsing MIFF. | |
| Modificada | Media (5.4) | 0.75% | — | Mygraph Project Mygraph | 24/9/2022 | 17/6/2026 | MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading to Remote Code Execution. This issue is patched in version 1.0.4. There is no known workaround. | |
| Modificada | Media (5.5) | 0.26% | — | IBM Common Cryptographic Architecture | 23/9/2022 | 17/6/2026 | IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to improper input validation. IBM X-Force ID: 223596. | |
| Modificada | Alta (7.5) | 2.6% | — | Graphql-java Project Graphql-java | 12/9/2022 | 17/6/2026 | graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, and 17.4, and 0.0.0-2022-07-26T05-45-04-226aabd9. | |
| Modificada | Alta (8.8) | 1.2% | — | Tigergraph | 5/9/2022 | 17/6/2026 | The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. Consequently, an attacker can execute arbitrary C++ code. NOTE: the vendor's position is "GSQL was behaving as expected." | |
| Modificada | Alta (7.5) | 1.0% | — | Graphql-go Project Graphql-go | 1/8/2022 | 25/8/2026 | graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser. | |
| Modificada | Media (4.3) | 0.49% | — | Sourcegraph | 1/8/2022 | 17/6/2026 | Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authorization check. The vulnerability does not allow the reading of other users’ saved searches, only overwriting them with… | |
| Modificada | Media (4.3) | 0.49% | — | Sourcegraph | 1/8/2022 | 17/6/2026 | Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the Code Monitors owned by any other Sourcegraph user. This includes being able to edit both the trigger and the action of the monitor in question. An attacker is not able to read contents of… | |
| Modificada | Media (6.4) | 0.58% | — | Kippo-graph Project Kippo-graph | 28/7/2022 | 17/6/2026 | In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in $file_link in class/KippoInput.class.php. | |
| Modificada | Media (6.4) | 0.57% | — | Kippo-graph Project Kippo-graph | 28/7/2022 | 17/6/2026 | In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in xss_clean() in class/KippoInput.class.php. | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Crítica (9.8) | 1.8% | — | Siemens Biograph Horizon Pet/ct Systems FirmwareSiemens Magnetom Numaris X FirmwareSiemens Mammomat Revelation FirmwareSiemens Naeotom Alpha Firmware+14 | 1/6/2022 | 17/6/2026 | A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40… | |
| Modificada | Crítica (9.8) | 1.8% | — | Graphql-upload Project Graphql-upload | 16/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename. | |
| Modificada | Media (5.3) | 1.8% | — | Wpgraphql | 9/5/2022 | 17/6/2026 | The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site. |