Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.68% | — | Vmware Spring FOR Graphql | 11/6/2026 | 23/7/2026 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can… | |
| Analizada | Media (5.3) | 0.69% | — | Strawberry Graphql | 4/6/2026 | 22/7/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a… | |
| Analizada | Media (5.3) | 0.43% | — | Strawberry Graphql | 4/6/2026 | 22/7/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circular fragment references the determine_depth function enters an… | |
| Analizada | Media (4.3) | 0.36% | — | Strawberry Graphql | 4/6/2026 | 22/7/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as `Authorization: Bearer <token>`, the value could become… | |
| Aplazada | Alta (8.7) | 0.45% | — | WpgraphqlAI | 15/5/2026 | 17/6/2026 | WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads to trigger server… | |
| Analizada | Alta (8.7) | 0.82% | — | Absinthe-graphql Absinthe | 8/5/2026 | 17/6/2026 | Inefficient Algorithmic Complexity vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service via quadratic fragment-name uniqueness validation. 'Elixir.Absinthe.Phase.Document.Validation.UniqueFragmentNames':run/2 iterates over all fragments and for each one calls duplicate?/2, which… | |
| Analizada | Baja (2.3) | 0.38% | — | Absinthe-graphql Absinthe.plug | 8/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows reflected cross-site scripting via the GraphiQL interface. 'Elixir.Absinthe.Plug.GraphiQL':js_escape/1 in lib/absinthe/plug/graphiql.ex escapes single quotes and newlines in the query GET parameter… | |
| Analizada | Alta (8.2) | 0.70% | — | Absinthe-graphql Absinthe | 8/5/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service via atom table exhaustion when parsing attacker-controlled GraphQL SDL. Multiple Blueprint.Draft.convert/2 implementations in Absinthe's SDL language modules call String.to_atom/1 on… | |
| Aplazada | Media (5.4) | 0.09% | — | WpgraphqlAI | 7/5/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGraphQL: from n/a through 2.5.3. | |
| Modificada | Media (6.9) | 0.73% | — | Webonyx Graphql-php | 17/4/2026 | 14/9/2026 | graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with thousands of repeated identical fields, causing excessive CPU usage during… | |
| Analizada | Alta (8.1) | 0.34% | — | Apollographql Apollo MCP Server | 9/4/2026 | 17/6/2026 | Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.0, the Apollo MCP Server did not validate the Host header on incoming HTTP requests when using StreamableHTTP transport. In configurations where an HTTP-based MCP server is run on localhost without… | |
| Analizada | Alta (7.5) | 0.60% | — | Strawberry Graphql | 7/4/2026 | 17/6/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler does not verify that a connection_init handshake has been completed before processing start… | |
| Analizada | Alta (7.5) | 0.48% | — | Strawberry Graphql | 7/4/2026 | 17/6/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphql-transport-ws and legacy graphql-ws protocols allocate an asyncio.Task and associated Operation object for every incoming subscribe message without enforcing any limit… | |
| Analizada | Alta (8.8) | 0.54% | — | SSW Tinacms/graphql | 1/4/2026 | 17/6/2026 | Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversal, but it does not resolve symlink or junction targets. If a symlink/junction already exists under the allowed content root, a path like… | |
| Analizada | Alta (8.1) | 0.63% | — | SSW Tinacms/graphql | 1/4/2026 | 17/6/2026 | Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The impact includes the… | |
| Aplazada | Media (4.3) | 0.29% | — | WpgraphqlAI | 24/3/2026 | 17/6/2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.10.0, an authorization flaw in updateComment allows an authenticated low-privileged user (including a custom role with zero capabilities) to change moderation status of their own comment (for example to APPROVE) without the moderate_comments… | |
| Analizada | Media (6.3) | 0.43% | — | SSW Tinacms/graphql | 12/3/2026 | 17/6/2026 | Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths are combined with the collection path using path.join() without… | |
| Aplazada | Alta (7.7) | 1.4% | — | WpgraphqlAI | 26/2/2026 | 17/6/2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command injection through direct use of `${{ github.event.pull_request.body }}` inside a `run:` shell block. When a pull request from… | |
| Analizada | Alta (7.5) | 0.70% | — | Apollographql Apollo Server | 4/2/2026 | 17/6/2026 | Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apollo Client. In versions from 2.0.0 to 3.13.0, 4.2.0 to before 4.13.0, and 5.0.0 to before 5.4.0, the default configuration of startStandaloneServer from @apollo/server/standalone is vulnerable to… | |
| Analizada | Crítica (9.3) | 1.1% | — | Hasura Graphql Engine | 21/1/2026 | 17/6/2026 | Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL's COPY FROM PROGRAM… | |
| Aplazada | Alta (8.7) | 0.57% | — | Graphql ModulesAI | 16/1/2026 | 17/6/2026 | GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are made which trigger the same service, the context of the requests is mixed up in the… | |
| Analizada | Media (6.9) | 0.38% | — | Hasura Graphql Engine | 22/12/2025 | 17/6/2026 | Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to the /v1/query endpoint with malicious URL definitions to potentially… | |
| Modificada | Media (6.9) | 0.22% | — | Hasura Graphql Engine | 22/12/2025 | 17/6/2026 | Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server. | |
| Analizada | Alta (8.7) | 0.48% | — | Hasura Graphql Engine | 22/12/2025 | 17/6/2026 | Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings and multiple threads to consume server resources and potentially… | |
| Analizada | Alta (7.3) | 0.48% | — | SSW TinacmsSSW Tinacms/cliSSW Tinacms/graphql | 18/12/2025 | 6/10/2026 | Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code. tinacms version 3.1.1, @tinacms/cli version 2.0.4, and… |