Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.43% | — | Demtec GraphyticsAI | 15/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part of the file /visualization of the component HTTP GET Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Crítica (9.1) | 0.35% | — | Graphicsmagick | 9/4/2025 | 17/6/2026 | GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call. | |
| Analizada | Alta (7.5) | 0.58% | — | Apollographql Apollo Gateway | 7/4/2025 | 17/6/2026 | Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically due to internal optimizations being… | |
| Analizada | Alta (7.5) | 0.51% | — | Apollographql Apollo Gateway | 7/4/2025 | 17/6/2026 | Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically during named fragment expansion.… | |
| Aplazada | Media (6.5) | 0.36% | — | Photoshelter FOR Photographers Blog Feed PluginAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PhotoShelter PhotoShelter for Photographers Blog Feed Plugin photoshelter-official-plugin allows Stored XSS.This issue affects PhotoShelter for Photographers Blog Feed Plugin: from n/a through <= 1.5.7. | |
| Aplazada | Alta (7.1) | 0.36% | — | Pixobe CartographyAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixobe Pixobe Cartography pixobe-cartography allows Reflected XSS.This issue affects Pixobe Cartography: from n/a through <= 1.0.1. | |
| Analizada | Alta (7.1) | 0.16% | — | Rivercitygraphix Limit BIO | 13/3/2025 | 17/6/2026 | The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Analizada | Alta (7.1) | 0.27% | — | Rivercitygraphix Limit BIO | 13/3/2025 | 17/6/2026 | The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Crítica (9) | 3.1% | 💥 PoC | Graphql RubyAI | 12/3/2025 | 17/6/2026 | graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution. Any… | |
| Analizada | Media (6.5) | 0.38% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests. | |
| Analizada | Baja (3.7) | 0.26% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations. | |
| Analizada | Media (6.5) | 0.44% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack. | |
| Analizada | Crítica (9.8) | 0.39% | — | Graphicsmagick | 7/3/2025 | 17/6/2026 | ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob. | |
| Analizada | Alta (7.5) | 0.45% | — | Graphicsmagick | 7/3/2025 | 17/6/2026 | ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. | |
| Aplazada | Media (6.5) | 0.38% | — | Themographics ListingoAI | 5/3/2025 | 17/6/2026 | The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (6.1) | 0.29% | — | Wpo365 Microsoft 365 Graph Mailer | 24/2/2025 | 17/6/2026 | The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to… | |
| Analizada | Alta (7.5) | 0.36% | — | The-guild Graphql Mesh CLIThe-guild Graphql Mesh Http | 20/2/2025 | 17/6/2026 | GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. Missing check vulnerability in the static file handler allows any client to access the… | |
| Analizada | Media (5.1) | 0.43% | — | The-guild Graphql Mesh | 20/2/2025 | 17/6/2026 | GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on the root level or single source with transforms, and the client… | |
| Analizada | Alta (7.5) | 0.18% | — | Intel Integrated Performance Primitives Cryptography | 14/2/2025 | 17/6/2026 | Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access. | |
| Aplazada | Media (6.3) | 0.29% | — | Themegoods PhotographyAI | 14/2/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photography: from n/a through <= 7.7.2. | |
| Aplazada | Media (6.8) | 0.20% | — | Intel Graphics DriversAI | 12/2/2025 | 17/6/2026 | Improper input validation in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (5.4) | 0.21% | — | Intel Graphics DriverAI | 12/2/2025 | 17/6/2026 | Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.5) | 0.21% | — | Intel Graphics SoftwareAI | 12/2/2025 | 17/6/2026 | Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.5) | 0.47% | — | AI Infographic MakerAI | 31/1/2025 | 17/6/2026 | The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.9.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.4) | 0.28% | — | Graph LiteAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in wptasker WordPress Graphs & Charts graph-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Graphs & Charts: from n/a through <= 2.0.8. |