Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.53% | — | Vtex Apps-graphql | 31/3/2023 | 17/6/2026 | The VTEX apps-graphql@2.x GraphQL API module does not properly restrict unauthorized access to private configuration data. (apps-graphql@3.x is unaffected by this issue.) | |
| Modificada | Alta (7.5) | 1.1% | — | Graphql-java | 27/3/2023 | 17/6/2026 | In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135. | |
| Modificada | Alta (7.5) | 1.1% | — | Silverstripe Graphql | 16/3/2023 | 17/6/2026 | `silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly affects websites with particularly… | |
| Modificada | Alta (7.5) | 1.3% | — | Hasura Graphql Engine | 14/3/2023 | 17/6/2026 | Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL Engine prior to versions 1.3.4, 2.55.1, 2.20.1, and 2.21.0-beta1. Projects running on Hasura Cloud were not vulnerable. Self-hosted Hasura Projects with deployments that… | |
| Modificada | Alta (8.8) | 0.85% | — | Hasura Graphql Engine | 8/12/2022 | 17/6/2026 | Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.) | |
| Modificada | Media (5.3) | 1.4% | — | Ibexa Ezplatform-graphql | 10/11/2022 | 17/6/2026 | ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically… | |
| Modificada | Alta (7.5) | 2.6% | — | Graphql-java Project Graphql-java | 12/9/2022 | 17/6/2026 | graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, and 17.4, and 0.0.0-2022-07-26T05-45-04-226aabd9. | |
| Modificada | Alta (7.5) | 1.0% | — | Graphql-go Project Graphql-go | 1/8/2022 | 25/8/2026 | graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser. | |
| Modificada | Crítica (9.8) | 1.8% | — | Graphql-upload Project Graphql-upload | 16/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename. | |
| Modificada | Media (5.3) | 1.8% | — | Wpgraphql | 9/5/2022 | 17/6/2026 | The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site. | |
| Modificada | Media (6.5) | 1.2% | — | Graphql-go Project Graphql-go | 21/1/2022 | 17/6/2026 | graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability that is possible due to a bug in the library that would allow an attacker with specifically designed queries to cause stack overflow panics. Any user with access to the GraphQL handler can send these… | |
| Modificada | Media (4.7) | 1.3% | — | Graphql Graphiql | 4/11/2021 | 17/6/2026 | GraphiQL is the reference implementation of this monorepo, GraphQL IDE, an official project under the GraphQL Foundation. All versions of graphiql older than graphiql@1.4.7 are vulnerable to compromised HTTP schema introspection responses or schema prop values with malicious GraphQL type names, exposing a dynamic XSS… | |
| Modificada | Media (4.7) | 1.2% | — | Graphql Playground | 4/11/2021 | 17/6/2026 | GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-react older than graphql-playground-react@1.7.28 are vulnerable to compromised HTTP schema introspection responses or schema prop values with malicious GraphQL type names, exposing a dynamic XSS… | |
| Modificada | Alta (8.8) | 2.8% | — | The-guild Graphql-tools | 20/1/2021 | 17/6/2026 | This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection. | |
| Modificada | Alta (7.4) | 7.2% | — | Prisma Graphql-playground-htmlPrisma Graphql-playground-middleware-expressPrisma Graphql-playground-middleware-hapiPrisma Graphql-playground-middleware-koa+1 | 8/6/2020 | 17/6/2026 | GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the… | |
| Modificada | Alta (7.5) | 1.2% | — | Hasura Graphql Engine | 29/7/2019 | 17/6/2026 | graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT. | |
| Modificada | Media (5.3) | 19% | — | Wpengine Wpgraphql | 10/6/2019 | 17/6/2026 | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled. | |
| Modificada | Crítica (9.1) | 36% | — | Wpengine Wpgraphql | 10/6/2019 | 17/6/2026 | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username. | |
| Modificada | Crítica (9.8) | 47% | — | Wpengine Wpgraphql | 10/6/2019 | 17/6/2026 | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation. |