Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.58% | — | Apollographql Apollo Gateway | 7/4/2025 | 17/6/2026 | Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically due to internal optimizations being… | |
| Analizada | Alta (7.5) | 0.51% | — | Apollographql Apollo Gateway | 7/4/2025 | 17/6/2026 | Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically during named fragment expansion.… | |
| Aplazada | Crítica (9) | 3.1% | — | Graphql RubyAI | 12/3/2025 | 17/6/2026 | graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution. Any… | |
| Analizada | Alta (7.5) | 0.36% | — | The-guild Graphql Mesh CLIThe-guild Graphql Mesh Http | 20/2/2025 | 17/6/2026 | GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. Missing check vulnerability in the static file handler allows any client to access the… | |
| Analizada | Media (5.1) | 0.43% | — | The-guild Graphql Mesh | 20/2/2025 | 17/6/2026 | GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on the root level or single source with transforms, and the client… | |
| Aplazada | Baja (3.7) | 0.38% | — | DjangoAISqlalchemyAIPydanticAIStrawberry GraphqlAI | 9/1/2025 | 17/6/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability occurs when multiple GraphQL types are… | |
| Aplazada | Media (6.8) | 0.18% | — | Altair Graphql ClientAI | 9/12/2024 | 17/6/2026 | Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle to intercept all requests. Any Altair users on untrusted networks (eg. public wifi, malicious DNS servers) may have all GraphQL request and… | |
| Aplazada | Media (5.5) | 0.36% | — | Aimeos Graphql APIAI | 24/10/2024 | 17/6/2026 | Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue. | |
| Aplazada | Alta (7.5) | 0.58% | — | Async-graphqlAI | 3/10/2024 | 17/6/2026 | async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion, and User Experience Degradation. This vulnerability is fixed in 7.0.10. | |
| Analizada | Alta (7.5) | 0.86% | — | Apollographql Apollo-routerApollographql Apollo Helms-charts RouterApollographql Apollo Router | 27/8/2024 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if _all_ of the following are true: 1. The Apollo… | |
| Analizada | Alta (7.5) | 0.99% | — | Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+1 | 27/8/2024 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.… | |
| Aplazada | Media (5.3) | 0.94% | — | Graphql-java Graphql JavaAI | 30/7/2024 | 17/6/2026 | GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions. | |
| Modificada | Baja (3.8) | 0.43% | — | Aimeos Ai-admin-graphql | 2/7/2024 | 17/6/2026 | aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and… | |
| Aplazada | Alta (7.1) | 0.44% | — | Aimeos Ai-admin-graphqlAI | 2/7/2024 | 17/6/2026 | aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6… | |
| Analizada | Alta (7.5) | 0.77% | — | Apollographql Apollo Router | 21/3/2024 | 17/6/2026 | The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) type vulnerability. When receiving compressed HTTP payloads, affected versions of the Router evaluate the `limits.http_max_request_bytes`… | |
| Modificada | Media (6.1) | 0.39% | — | Apollographql Apollo Client | 30/1/2024 | 17/6/2026 | apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this vulnerability, an attacker would need to either inject malicious input (e.g. by redirecting a user to a… | |
| Modificada | Media (5.3) | 0.42% | — | Silverstripe Graphql | 23/1/2024 | 17/6/2026 | The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is greater than the number of records per page.… | |
| Modificada | Media (5.3) | 0.72% | — | Wpengine Wpgraphql | 16/1/2024 | 17/6/2026 | The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL. | |
| Modificada | Media (6.5) | 0.45% | — | Wpengine Wpgraphql | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5. | |
| Modificada | Alta (7.5) | 0.73% | — | Apollographql Apollo RouterApollographql Apollo Helms-charts Router | 18/10/2023 | 17/6/2026 | The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send… | |
| Modificada | Alta (7.5) | 0.90% | — | Silverstripe Graphql | 16/10/2023 | 17/6/2026 | silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS… | |
| Modificada | Alta (7.8) | 0.22% | — | Altairgraphql Altair | 4/10/2023 | 17/6/2026 | Altair is a GraphQL Client. Prior to version 5.2.5, the Altair GraphQL Client Desktop Application does not sanitize external URLs before passing them to the underlying system. Moreover, Altair GraphQL Client also does not isolate the context of the renderer process. This affects versions of the software running on… | |
| Modificada | Media (4.3) | 0.42% | — | Vmware Spring FOR Graphql | 20/9/2023 | 17/6/2026 | A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through… | |
| Modificada | Media (5.3) | 1.5% | — | Graphql | 20/9/2023 | 17/6/2026 | Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this… | |
| Modificada | Media (5.9) | 0.80% | — | Apollographql Apollo Router | 5/9/2023 | 17/6/2026 | The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when GraphQL Subscriptions are enabled. It can be… |