Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

927 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.43%—Demtec GraphyticsAI15/4/202517/6/2026
A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part of the file /visualization of the component HTTP GET Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed…
AnalizadaCrítica (9.1)0.35%—Graphicsmagick9/4/202517/6/2026
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.
AnalizadaAlta (7.5)0.58%—Apollographql Apollo Gateway7/4/202517/6/2026
Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically due to internal optimizations being…
AnalizadaAlta (7.5)0.51%—Apollographql Apollo Gateway7/4/202517/6/2026
Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically during named fragment expansion.…
AplazadaMedia (6.5)0.36%—Photoshelter FOR Photographers Blog Feed PluginAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PhotoShelter PhotoShelter for Photographers Blog Feed Plugin photoshelter-official-plugin allows Stored XSS.This issue affects PhotoShelter for Photographers Blog Feed Plugin: from n/a through <= 1.5.7.
AplazadaAlta (7.1)0.36%—Pixobe CartographyAI26/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixobe Pixobe Cartography pixobe-cartography allows Reflected XSS.This issue affects Pixobe Cartography: from n/a through <= 1.0.1.
AnalizadaAlta (7.1)0.16%—Rivercitygraphix Limit BIO13/3/202517/6/2026
The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
AnalizadaAlta (7.1)0.27%—Rivercitygraphix Limit BIO13/3/202517/6/2026
The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaCrítica (9)3.1%💥 PoCGraphql RubyAI12/3/202517/6/2026
graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution. Any…
AnalizadaMedia (6.5)0.38%—IBM Common Cryptographic Architecture11/3/202517/6/2026
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests.
AnalizadaBaja (3.7)0.26%—IBM Common Cryptographic Architecture11/3/202517/6/2026
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations.
AnalizadaMedia (6.5)0.44%—IBM Common Cryptographic Architecture11/3/202517/6/2026
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack.
AnalizadaCrítica (9.8)0.39%—Graphicsmagick7/3/202517/6/2026
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
AnalizadaAlta (7.5)0.45%—Graphicsmagick7/3/202517/6/2026
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
AplazadaMedia (6.5)0.38%—Themographics ListingoAI5/3/202517/6/2026
The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (6.1)0.29%—Wpo365 Microsoft 365 Graph Mailer24/2/202517/6/2026
The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to…
AnalizadaAlta (7.5)0.36%—The-guild Graphql Mesh CLIThe-guild Graphql Mesh Http20/2/202517/6/2026
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. Missing check vulnerability in the static file handler allows any client to access the…
AnalizadaMedia (5.1)0.43%—The-guild Graphql Mesh20/2/202517/6/2026
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on the root level or single source with transforms, and the client…
AnalizadaAlta (7.5)0.18%—Intel Integrated Performance Primitives Cryptography14/2/202517/6/2026
Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.
AplazadaMedia (6.3)0.29%—Themegoods PhotographyAI14/2/202517/6/2026
Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photography: from n/a through <= 7.7.2.
AplazadaMedia (6.8)0.20%—Intel Graphics DriversAI12/2/202517/6/2026
Improper input validation in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (5.4)0.21%—Intel Graphics DriverAI12/2/202517/6/2026
Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.5)0.21%—Intel Graphics SoftwareAI12/2/202517/6/2026
Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.5)0.47%—AI Infographic MakerAI31/1/202517/6/2026
The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.9.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated…
AplazadaMedia (5.4)0.28%—Graph LiteAI16/1/202517/6/2026
Missing Authorization vulnerability in wptasker WordPress Graphs & Charts graph-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Graphs & Charts: from n/a through <= 2.0.8.
Orbitaley — Vulnerabilidades