Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.2) | 0.27% | — | OpensslAIGoogle BoringsslAICryptography.io CryptographyAIOpenbsd LibresslAI | 3/8/2026 | 10/9/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the… | |
| Pendiente de análisis | Media (6.9) | 0.45% | — | WpgraphqlAI | 31/7/2026 | 10/9/2026 | WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in… | |
| Analizada | Media (6.5) | 1.00% | — | Microsoft Graph | 24/7/2026 | 29/7/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | |
| Aplazada | Media (5.3) | 0.31% | — | GraphinaAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Themegoods PhotographyAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Grand PhotographyAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions. | |
| Aplazada | Baja (3.3) | 0.14% | — | Data Graph SharedAI | 21/7/2026 | 23/7/2026 | Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is… | |
| Aplazada | Media (6.9) | 0.53% | — | Safishamsi GraphifyAI | 20/7/2026 | 23/7/2026 | An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary functions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Themegoods Grand PhotographyAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8. | |
| Analizada | Alta (8.1) | 0.43% | — | Plotly.js Graphing | 10/7/2026 | 14/7/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2. | |
| Analizada | Media (6.5) | 0.27% | — | Md-systems Paragraphs | 10/7/2026 | 21/7/2026 | Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. | |
| Analizada | Media (6.5) | 0.27% | — | Md-systems Paragraphs | 10/7/2026 | 21/7/2026 | Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. | |
| Aplazada | Crítica (9.1) | 0.58% | — | DgraphAI | 8/7/2026 | 8/7/2026 | Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream… | |
| Aplazada | Alta (7.5) | 0.49% | — | DgraphAI | 8/7/2026 | 9/7/2026 | Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is vulnerable to DQL (Dgraph Query Language) injection. User-supplied password values are interpolated directly into a DQL `checkpwd()` query via `fmt.Sprintf` without any escaping or… | |
| Analizada | Media (6) | 0.27% | — | Hasura Graphql Engine | 7/7/2026 | 17/8/2026 | Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table computed field (returning SETOF some_table) to infer row values that ought to be filtered for their role based on some_table's row-level permissions. While such rows cannot be… | |
| Aplazada | Baja (1.3) | 0.23% | — | Langchain LanggraphAI | 5/7/2026 | 6/7/2026 | A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. This manipulation of the argument default_cache_key causes use of weak hash. The attack is possible to be… | |
| Aplazada | Alta (7.1) | 0.25% | — | Artale Wedding PhotographyAI | 2/7/2026 | 5/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions. | |
| Analizada | Alta (8.8) | 0.43% | — | Nordmograph Streetguessr Game | 19/6/2026 | 21/8/2026 | Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the option=com_streetguess&view=maps parameters and inject SQL code in… | |
| Aplazada | Media (4.8) | 0.31% | — | Hashgraph GuardianAI | 18/6/2026 | 14/7/2026 | Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the… | |
| Analizada | Crítica (9.1) | 0.29% | — | Langchain Langgraph-sdk | 17/6/2026 | 26/6/2026 | LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations. Without… | |
| Analizada | Media (6.8) | 0.69% | — | Langchain Langgraph-checkpoint | 16/6/2026 | 24/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest… | |
| Aplazada | Alta (7.5) | 0.32% | — | WpgraphqlAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions. | |
| Analizada | Alta (7.5) | 0.39% | — | Vmware Spring FOR Graphql | 11/6/2026 | 23/7/2026 | The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected… | |
| Analizada | Alta (8.1) | 0.23% | — | Vmware Spring FOR Graphql | 11/6/2026 | 23/7/2026 | Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials. Affected versions: Spring… | |
| Analizada | Crítica (9.8) | 0.68% | — | Vmware Spring FOR Graphql | 11/6/2026 | 23/7/2026 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can… |