Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.14% | — | Themegoods Grand PhotographyAI | 8/4/2026 | 20/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a through <= 5.7.8. | |
| Analizada | Alta (7.5) | 0.60% | — | Strawberry Graphql | 7/4/2026 | 17/6/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler does not verify that a connection_init handshake has been completed before processing start… | |
| Analizada | Alta (7.5) | 0.48% | — | Strawberry Graphql | 7/4/2026 | 17/6/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphql-transport-ws and legacy graphql-ws protocols allocate an asyncio.Task and associated Operation object for every incoming subscribe message without enforcing any limit… | |
| Analizada | Crítica (10) | 1.7% | — | Dgraph | 6/4/2026 | 17/6/2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenticated. Unlike the similar restore mutation which requires Guardian-of-Galaxy authentication, restoreTenant executes… | |
| Aplazada | Baja (2.1) | 2.2% | — | Scrapegraph AIAI | 5/4/2026 | 24/7/2026 | A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the component GenerateCodeNode Component. The manipulation results in os command injection. The attack may be launched… | |
| Analizada | Alta (8.8) | 0.54% | — | SSW Tinacms/graphql | 1/4/2026 | 17/6/2026 | Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversal, but it does not resolve symlink or junction targets. If a symlink/junction already exists under the allowed content root, a path like… | |
| Analizada | Alta (8.1) | 0.63% | — | SSW Tinacms/graphql | 1/4/2026 | 17/6/2026 | Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The impact includes the… | |
| Analizada | Baja (1.7) | 0.17% | — | Cryptography.io Cryptography | 31/3/2026 | 17/6/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named… | |
| Aplazada | Media (4.3) | 0.29% | — | WpgraphqlAI | 24/3/2026 | 17/6/2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.10.0, an authorization flaw in updateComment allows an authenticated low-privileged user (including a custom role with zero capabilities) to change moderation status of their own comment (for example to APPROVE) without the moderate_comments… | |
| Analizada | Crítica (9.1) | 0.89% | — | Graphiti | 24/3/2026 | 17/6/2026 | Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to… | |
| Aplazada | Media (4.3) | 0.14% | — | ADD Google Social Profiles TO Knowledge Graph BOXAI | 21/3/2026 | 17/6/2026 | The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's… | |
| Aplazada | Alta (7.2) | 0.50% | — | Themegoods PhotographyAI | 19/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue affects Photography: from n/a before 7.7.6. | |
| Aplazada | Media (5.3) | 0.32% | — | Vowelweb VW PhotographyAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in vowelweb VW Photography vw-photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Photography: from n/a through <= 1.3.8. | |
| Analizada | Alta (8.1) | 0.48% | — | Getzep Graphiti | 12/3/2026 | 17/6/2026 | Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher injection vulnerability in shared search-filter construction for non-Kuzu backends. Attacker-controlled label values supplied through SearchFilters.node_labels were concatenated… | |
| Analizada | Media (6.3) | 0.43% | — | SSW Tinacms/graphql | 12/3/2026 | 17/6/2026 | Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths are combined with the collection path using path.join() without… | |
| Aplazada | Media (6.9) | 0.41% | — | Keygraph ShannonAI | 9/3/2026 | 14/7/2026 | Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network attackers to authenticate using the publicly known static key. An attacker able to reach the router port can proxy requests through the Shannon instance using the victim’s… | |
| Analizada | Media (5.3) | 0.38% | — | Thegraph Graph Protocol Contracts | 5/3/2026 | 17/6/2026 | The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows users to access tokens that should still be locked according to their vesting schedule. This issue has been patched in version 3.0.0. | |
| Analizada | Alta (7.2) | 0.70% | — | Langchain Langgraph | 5/3/2026 | 17/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint… | |
| Aplazada | Alta (7.1) | 0.26% | — | Themegoods PhotographyAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows DOM-Based XSS.This issue affects Photography: from n/a through < 7.7.6. | |
| Aplazada | Alta (7.7) | 1.4% | — | WpgraphqlAI | 26/2/2026 | 17/6/2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command injection through direct use of `${{ github.event.pull_request.body }}` inside a `run:` shell block. When a pull request from… | |
| Aplazada | Media (6.6) | 0.96% | — | Langchain Langgraph CheckpointAI | 25/2/2026 | 17/6/2026 | LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execution vulnerability exists in LangGraph's caching layer when applications enable cache backends that inherit from `BaseCache` and opt nodes into caching via `CachePolicy`. Prior to… | |
| Aplazada | Media (6.5) | 0.49% | — | Langchain Langgraph-checkpoint-redisAI | 20/2/2026 | 17/6/2026 | @langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating… | |
| Aplazada | Alta (7.1) | 0.24% | — | Gt3themes Soho - Photography Wordpress ThemeAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes SOHO - Photography WordPress Theme soho allows DOM-Based XSS.This issue affects SOHO - Photography WordPress Theme: from n/a through <= 3.0.3. | |
| Aplazada | Alta (7.1) | 0.27% | — | Gt3themes Oyster - Photography Wordpress ThemeAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Oyster - Photography WordPress Theme oyster allows DOM-Based XSS.This issue affects Oyster - Photography WordPress Theme: from n/a through <= 4.4.3. | |
| Aplazada | Media (4.3) | 0.18% | — | Page Title Description Open Graph UpdaterAI | 19/2/2026 | 17/6/2026 | The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.02. This is due to missing nonce validation on multiple AJAX actions including dieno_update_page_title. This makes it possible for unauthenticated attackers to… |