Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

927 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.2)0.27%—OpensslAIGoogle BoringsslAICryptography.io CryptographyAIOpenbsd LibresslAI3/8/202610/9/2026
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the…
Pendiente de análisisMedia (6.9)0.45%—WpgraphqlAI31/7/202610/9/2026
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in…
AnalizadaMedia (6.5)1.00%—Microsoft Graph24/7/202629/7/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
AplazadaMedia (5.3)0.31%—GraphinaAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
AplazadaMedia (5.3)0.29%—Themegoods PhotographyAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
AplazadaAlta (7.1)0.25%—Grand PhotographyAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
AplazadaBaja (3.3)0.14%—Data Graph SharedAI21/7/202623/7/2026
Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is…
AplazadaMedia (6.9)0.53%—Safishamsi GraphifyAI20/7/202623/7/2026
An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary functions.
AplazadaCrítica (9.8)0.56%—Themegoods Grand PhotographyAI13/7/202613/7/2026
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
AnalizadaAlta (8.1)0.43%—Plotly.js Graphing10/7/202614/7/2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.
AnalizadaMedia (6.5)0.27%—Md-systems Paragraphs10/7/202621/7/2026
Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
AnalizadaMedia (6.5)0.27%—Md-systems Paragraphs10/7/202621/7/2026
Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
AplazadaCrítica (9.1)0.58%—DgraphAI8/7/20268/7/2026
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream…
AplazadaAlta (7.5)0.49%—DgraphAI8/7/20269/7/2026
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is vulnerable to DQL (Dgraph Query Language) injection. User-supplied password values are interpolated directly into a DQL `checkpwd()` query via `fmt.Sprintf` without any escaping or…
AnalizadaMedia (6)0.27%—Hasura Graphql Engine7/7/202617/8/2026
Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table computed field (returning SETOF some_table) to infer row values that ought to be filtered for their role based on some_table's row-level permissions. While such rows cannot be…
AplazadaBaja (1.3)0.23%—Langchain LanggraphAI5/7/20266/7/2026
A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. This manipulation of the argument default_cache_key causes use of weak hash. The attack is possible to be…
AplazadaAlta (7.1)0.25%—Artale Wedding PhotographyAI2/7/20265/10/2026
Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.
AnalizadaAlta (8.8)0.43%—Nordmograph Streetguessr Game19/6/202621/8/2026
Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the option=com_streetguess&view=maps parameters and inject SQL code in…
AplazadaMedia (4.8)0.31%—Hashgraph GuardianAI18/6/202614/7/2026
Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the…
AnalizadaCrítica (9.1)0.29%—Langchain Langgraph-sdk17/6/202626/6/2026
LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations. Without…
AnalizadaMedia (6.8)0.69%—Langchain Langgraph-checkpoint16/6/202624/6/2026
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest…
AplazadaAlta (7.5)0.32%—WpgraphqlAI15/6/202617/6/2026
Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.
AnalizadaAlta (7.5)0.39%—Vmware Spring FOR Graphql11/6/202623/7/2026
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected…
AnalizadaAlta (8.1)0.23%—Vmware Spring FOR Graphql11/6/202623/7/2026
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials. Affected versions: Spring…
AnalizadaCrítica (9.8)0.68%—Vmware Spring FOR Graphql11/6/202623/7/2026
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can…