Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.28% | — | Percent TO InfographAI | 14/2/2026 | 17/6/2026 | The Percent to Infograph plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `percent_to_graph` shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.9) | 0.14% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service. | |
| Aplazada | Alta (8.8) | 0.17% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution. | |
| Aplazada | Media (5.5) | 0.16% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially resulting in a denial of service | |
| Modificada | Alta (8.2) | 0.35% | — | Cryptography.io Cryptography | 10/2/2026 | 10/9/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the… | |
| Analizada | Baja (2) | 0.09% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Alta (8.2) | 0.47% | 💥 PoC | Nukegraphic CMSAI | 5/2/2026 | 17/6/2026 | Nukegraphic CMS v3.1.2 contains a stored cross-site scripting (XSS) vulnerability in the user profile edit functionality at /ngc-cms/user-edit-profile.php. The application fails to properly sanitize user input in the name field before storing it in the database and rendering it across multiple CMS pages. An… | |
| Aplazada | Crítica (9.8) | 0.56% | — | IBM Common Cryptographic ArchitectureAI | 4/2/2026 | 17/6/2026 | IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system. | |
| Analizada | Alta (7.5) | 0.70% | — | Apollographql Apollo Server | 4/2/2026 | 17/6/2026 | Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apollo Client. In versions from 2.0.0 to 3.13.0, 4.2.0 to before 4.13.0, and 5.0.0 to before 5.4.0, the default configuration of startStandaloneServer from @apollo/server/standalone is vulnerable to… | |
| Aplazada | Alta (8.1) | 0.47% | — | Themegoods PhotographyAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeGoods Photography photography allows PHP Local File Inclusion.This issue affects Photography: from n/a through < 7.7.5. | |
| Aplazada | Media (6.7) | 0.28% | — | Geogebra Graphing CalculatorAI | 21/1/2026 | 17/6/2026 | GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer. Attackers can generate a payload of 8000 repeated characters to overwhelm the input field and cause the application to become unresponsive. | |
| Analizada | Crítica (9.3) | 1.1% | — | Hasura Graphql Engine | 21/1/2026 | 17/6/2026 | Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL's COPY FROM PROGRAM… | |
| Aplazada | Alta (8.7) | 0.57% | — | Graphql ModulesAI | 16/1/2026 | 17/6/2026 | GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are made which trigger the same service, the context of the requests is mixed up in the… | |
| Analizada | Alta (7.8) | 0.93% | — | Nvidia Nsight Graphics | 14/1/2026 | 17/6/2026 | NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service. | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove Graphist FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Select Graphist for Elementor Graphist for Elementor graphist-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Select Graphist for Elementor Graphist for Elementor: from n/a through <= 1.2.10. | |
| Aplazada | Media (6.5) | 0.15% | — | Codeflavors Featured Video FOR Wordpress VideographywpAI | 30/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeFlavors Featured Video for WordPress – VideographyWP videographywp allows Stored XSS.This issue affects Featured Video for WordPress – VideographyWP: from n/a through <= 1.0.18. | |
| Analizada | Media (6.9) | 0.38% | — | Hasura Graphql Engine | 22/12/2025 | 17/6/2026 | Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to the /v1/query endpoint with malicious URL definitions to potentially… | |
| Modificada | Media (6.9) | 0.22% | — | Hasura Graphql Engine | 22/12/2025 | 17/6/2026 | Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server. | |
| Analizada | Alta (8.7) | 0.48% | — | Hasura Graphql Engine | 22/12/2025 | 17/6/2026 | Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings and multiple threads to consume server resources and potentially… | |
| Analizada | Alta (7.3) | 0.48% | — | SSW TinacmsSSW Tinacms/cliSSW Tinacms/graphql | 18/12/2025 | 6/10/2026 | Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code. tinacms version 3.1.1, @tinacms/cli version 2.0.4, and… | |
| Analizada | Alta (7.1) | 0.21% | — | Themegoods Photography | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows Reflected XSS.This issue affects Photography: from n/a through <= 7.7.2. | |
| Analizada | Alta (8.8) | 0.89% | — | Apache Hugegraph | 12/12/2025 | 17/6/2026 | A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection… | |
| Analizada | Alta (7.8) | 2.3% | 💥 PoC | Langchain Langgraph-checkpoint-sqlite | 11/12/2025 | 17/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.0 and below are vulnerable to SQL injection through the checkpoint implementation. Checkpoint allows attackers to manipulate SQL queries through metadata filter keys,… |