Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.28% | — | Gmod ApolloAI | 5/3/2025 | 17/6/2026 | GMOD Apollo does not have sufficient logical or access checks when updating a user's information. This could result in an attacker being able to escalate privileges for themselves or others. | |
| Aplazada | Media (6.9) | 0.31% | — | Gmod ApolloAI | 5/3/2025 | 17/6/2026 | After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with local path information disclosure | |
| Analizada | Media (5.4) | 0.30% | — | Apollo13 Rife Elementor Extensions & Templates | 22/2/2025 | 17/6/2026 | The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.19% | — | Apollo13themes Rife FreeAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in apollo13themes Rife Free rife-free allows Cross Site Request Forgery.This issue affects Rife Free: from n/a through <= 2.4.18. | |
| Aplazada | Media (5.4) | 0.47% | — | Apollo13themes Rife Elementor Extensions AND TemplatesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Apollo13Themes Rife Elementor Extensions & Templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rife Elementor Extensions & Templates: from n/a through 1.1.10. | |
| Aplazada | Media (5.4) | 0.59% | — | Apollo13themes Apollo13 Framework ExtensionsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apollo13 Framework Extensions: from n/a through 1.8.10. | |
| Analizada | Alta (7.5) | 0.86% | — | Apollographql Apollo-routerApollographql Apollo Helms-charts RouterApollographql Apollo Router | 27/8/2024 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if _all_ of the following are true: 1. The Apollo… | |
| Analizada | Alta (7.5) | 0.99% | — | Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+1 | 27/8/2024 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.… | |
| Analizada | Media (4.3) | 0.35% | — | Apolloconfig Apollo | 20/8/2024 | 17/6/2026 | Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with an input parameter… | |
| Modificada | Alta (7.5) | 0.53% | — | Apolloconfig Apollo | 20/8/2024 | 17/6/2026 | An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request. | |
| Modificada | Media (5.4) | 0.31% | — | Apollo13themes Apollo13 Framework Extensions | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions apollo13-framework-extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.3. | |
| Modificada | Media (5.4) | 0.35% | — | Apollo13themes Rife Elementor Extensions & Templates | 2/7/2024 | 17/6/2026 | The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute within the plugin's Writing Effect Headline widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Media (5.4) | 0.26% | — | Apollo13themes Rife Free | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in apollo13themes Rife Free allows Stored XSS.This issue affects Rife Free: from n/a through 2.4.19. | |
| Aplazada | Crítica (9) | 0.73% | — | Apollo RouterAI | 2/5/2024 | 17/6/2026 | Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. The affected versions of Apollo Router contain a bug that in limited circumstances, could lead to unexpected operations being executed which can result in unintended data or effects. This only… | |
| Modificada | Alta (7.5) | 4.3% | — | Wyrestorm Apollo Vx20 Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request. | |
| Modificada | Crítica (9.1) | 51% | — | Wyrestorm Apollo Vx20 Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request. | |
| Modificada | Alta (7.5) | 4.1% | — | Wyrestorm Apollo Vx20 Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts. | |
| Analizada | Alta (7.5) | 0.77% | — | Apollographql Apollo Router | 21/3/2024 | 17/6/2026 | The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) type vulnerability. When receiving compressed HTTP payloads, affected versions of the Router evaluate the `limits.http_max_request_bytes`… | |
| Modificada | Media (5.4) | 0.32% | — | Apollo13themes Apollo13 Framework Extensions | 8/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.2. | |
| Modificada | Media (6.1) | 0.39% | — | Apollographql Apollo Client | 30/1/2024 | 17/6/2026 | apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this vulnerability, an attacker would need to either inject malicious input (e.g. by redirecting a user to a… | |
| Modificada | Media (4.3) | 0.46% | — | Apolloconfig Apollo | 12/1/2024 | 17/6/2026 | A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the component Configuration Center. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.22% | — | Apollo13themes Apollo13 Framework Extensions | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Apollo13Themes Apollo13 Framework Extensions.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.1. | |
| Modificada | Media (5.4) | 0.39% | — | Apollo13themes Apollo13 Framework Extensions | 8/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plugin <= 1.9.0 versions. | |
| Modificada | Alta (7.5) | 0.73% | — | Apollographql Apollo RouterApollographql Apollo Helms-charts Router | 18/10/2023 | 17/6/2026 | The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send… | |
| Modificada | Media (5.4) | 0.36% | — | Palantir Apollo Autopilot | 27/9/2023 | 17/6/2026 | In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction. |