Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.26% | — | Kiran Potphode Easy ChartsAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Potphode Easy Charts easy-charts allows DOM-Based XSS.This issue affects Easy Charts: from n/a through <= 1.2.3. | |
| Analizada | Media (5.8) | 0.43% | — | Openfga Helm ChartsOpenfga | 19/2/2025 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users on OpenFGA v1.8.4 or… | |
| Analizada | Media (5.4) | 0.25% | — | Supporthost Simple Charts | 18/2/2025 | 17/6/2026 | The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.24% | — | Dotstore Product Size Charts Plugin FOR WoocommerceAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Product Size Charts Plugin for WooCommerce woo-advanced-product-size-chart.This issue affects Product Size Charts Plugin for WooCommerce: from n/a through <= 2.4.5. | |
| Analizada | Media (5.4) | 0.22% | — | Nfusionsolutions Precious Metals Charts AND Widgets | 24/1/2025 | 17/6/2026 | The Precious Metals Charts and Widgets for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nfusion-widget' shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Analizada | Media (5.8) | 0.45% | — | Openfga Helm ChartsOpenfga | 13/1/2025 | 17/6/2026 | OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObjects with a model that uses… | |
| Analizada | Media (5.4) | 0.23% | — | IBM Carbon Charts | 10/12/2024 | 17/6/2026 | IBM Carbon Design System (Carbon Charts 0.4.0 through 1.13.16) is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Media (6.5) | 0.32% | — | Baptiste Wicht Google-visualization-chartsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Baptiste Wicht Google Visualization Charts google-visualization-charts allows Stored XSS.This issue affects Google Visualization Charts: from n/a through <= 0.1. | |
| Modificada | Media (5.4) | 0.25% | — | Chartscss Coub | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coub Coub coub allows DOM-Based XSS.This issue affects Coub: from n/a through <= 1.4. | |
| Analizada | Media (6.1) | 0.38% | — | Amcharts\ | 12/9/2024 | 17/6/2026 | The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, 1.4.4 due to the ability to supply arbitrary JavaScript a lack of nonce validation on the preview functionality. This makes it possible for… | |
| Analizada | Alta (7.5) | 0.86% | — | Apollographql Apollo-routerApollographql Apollo Helms-charts RouterApollographql Apollo Router | 27/8/2024 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if _all_ of the following are true: 1. The Apollo… | |
| Analizada | Alta (7.5) | 0.99% | — | Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+1 | 27/8/2024 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.… | |
| Analizada | Media (6.3) | 0.83% | — | Ag-gridAg-grid AG Charts | 1/7/2024 | 17/6/2026 | ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Modificada | Media (4.8) | 0.39% | — | Goldbroker Live Gold Price & Silver Price Charts Widgets | 14/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GoldBroker.Com Live Gold Price & Silver Price Charts Widgets plugin <= 2.4 versions. | |
| Modificada | Alta (7.5) | 0.73% | — | Apollographql Apollo RouterApollographql Apollo Helms-charts Router | 18/10/2023 | 17/6/2026 | The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send… | |
| Modificada | Media (5.4) | 0.51% | — | Wpartisan Wordpress Charts | 20/9/2023 | 17/6/2026 | The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in versions up to, and including, 0.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Media (4.8) | 0.37% | — | Stock Market Charts From Finviz | 3/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Moris Dov Stock market charts from finviz plugin <= 1.0.1 versions. | |
| Modificada | Media (5.4) | 0.84% | — | Smoothiecharts Smoothie Charts | 21/12/2022 | 17/6/2026 | The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties. | |
| Modificada | Media (5.4) | 0.56% | — | Amcharts\ | 23/8/2022 | 17/6/2026 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in amCharts: Charts and Maps plugin <= 1.4 at WordPress. | |
| Modificada | Media (6.5) | 0.92% | — | Jenkins Dbcharts | 15/3/2022 | 17/6/2026 | Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Alta (8.8) | 0.79% | — | Jenkins Dbcharts | 15/2/2022 | 17/6/2026 | A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials. | |
| Modificada | Alta (8.8) | 0.53% | — | Jenkins Dbcharts | 15/2/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance. | |
| Modificada | Media (5.4) | 0.87% | — | HighchartsNetapp Cloud BackupNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 5/5/2021 | 17/6/2026 | Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options structure was not systematically filtered for XSS vectors. The potential impact was that content from untrusted sources could execute code in the end user's browser. The vulnerability is patched in… | |
| Modificada | Media (6.3) | 1.4% | — | Fusioncharts Apexcharts | 9/2/2021 | 17/6/2026 | The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields. | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Flexmonster Pivot Table & Charts | 17/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17. |