Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

927 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to…
ModificadaCrítica (9.8)1.1%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe…
ModificadaMedia (5.4)0.79%—Graphite Project Graphite27/12/202217/6/2026
A vulnerability was found in Graphite Web. It has been classified as problematic. Affected is an unknown function of the component Absolute Time Range Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaMedia (5.4)0.76%—Graphite Project Graphite27/12/202217/6/2026
A vulnerability was found in Graphite Web and classified as problematic. This issue affects some unknown processing of the component Template Name Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the…
ModificadaMedia (5.4)0.79%—Graphite Project Graphite27/12/202217/6/2026
A vulnerability has been found in Graphite Web and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the…
ModificadaCrítica (9.8)21%—Themographics Listingo12/12/202217/6/2026
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE
ModificadaAlta (8.8)0.85%—Hasura Graphql Engine8/12/202217/6/2026
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)
ModificadaAlta (7.2)1.8%—Sourcegraph22/11/202217/6/2026
sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0.
ModificadaAlta (7.8)2.8%—Sourcegraph22/11/202217/6/2026
Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. This vulnerability was caused by a lack of input validation on the host parameter of the `/list-gitolite` endpoint. It was possible to send…
ModificadaMedia (5.3)1.4%💥 PoCIbexa Ezplatform-graphql10/11/202217/6/2026
ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically…
ModificadaMedia (6.1)0.63%—Jgraph Mxgraph12/10/20229/7/2026
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
ModificadaAlta (7.8)0.46%—GraphicsmagickDebian Linux28/9/202217/6/2026
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
ModificadaMedia (5.4)0.75%—Mygraph Project Mygraph24/9/202217/6/2026
MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading to Remote Code Execution. This issue is patched in version 1.0.4. There is no known workaround.
ModificadaMedia (5.5)0.26%—IBM Common Cryptographic Architecture23/9/202217/6/2026
IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to improper input validation. IBM X-Force ID: 223596.
ModificadaAlta (7.5)2.6%—Graphql-java Project Graphql-java12/9/202217/6/2026
graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, and 17.4, and 0.0.0-2022-07-26T05-45-04-226aabd9.
ModificadaAlta (8.8)1.2%—Tigergraph5/9/202217/6/2026
The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. Consequently, an attacker can execute arbitrary C++ code. NOTE: the vendor's position is "GSQL was behaving as expected."
ModificadaAlta (7.5)1.0%—Graphql-go Project Graphql-go1/8/202225/8/2026
graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.
ModificadaMedia (4.3)0.49%—Sourcegraph1/8/202217/6/2026
Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authorization check. The vulnerability does not allow the reading of other users’ saved searches, only overwriting them with…
ModificadaMedia (4.3)0.49%—Sourcegraph1/8/202217/6/2026
Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the Code Monitors owned by any other Sourcegraph user. This includes being able to edit both the trigger and the action of the monitor in question. An attacker is not able to read contents of…
ModificadaMedia (6.4)0.58%—Kippo-graph Project Kippo-graph28/7/202217/6/2026
In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in $file_link in class/KippoInput.class.php.
ModificadaMedia (6.4)0.57%—Kippo-graph Project Kippo-graph28/7/202217/6/2026
In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in xss_clean() in class/KippoInput.class.php.
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaCrítica (9.8)1.8%—Siemens Biograph Horizon Pet/ct Systems FirmwareSiemens Magnetom Numaris X FirmwareSiemens Mammomat Revelation FirmwareSiemens Naeotom Alpha Firmware+141/6/202217/6/2026
A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40…
ModificadaCrítica (9.8)1.8%—Graphql-upload Project Graphql-upload16/5/202217/6/2026
An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename.
ModificadaMedia (5.3)1.8%—Wpgraphql9/5/202217/6/2026
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.
Orbitaley — Vulnerabilidades