Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 8 respecto a la semana anterior
Críticas / altas1461▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.2) | 0.44% | — | Akana API PlatformAI | 11/9/2026 | 18/9/2026 | A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a… | |
| Aplazada | Crítica (10) | 1.4% | — | Akana API PlatformAI | 9/9/2026 | 9/9/2026 | An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied… | |
| Aplazada | Media (6.5) | 0.34% | — | Api-platform API Platform CoreAI | 1/7/2026 | 2/7/2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's AbstractItemNormalizer does not validate the resource type returned when resolving relation IRIs, allowing type confusion where a resource of an unintended type can be… | |
| Pendiente de análisis | Media (5.9) | 0.32% | — | Api-platform API Platform CoreAI | 1/7/2026 | 2/7/2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing isCacheKeySafe gate in the JSON:API and HAL item normalizers causes a cross-user attribute leak. #[ApiProperty(security: ...)] is evaluated per request to decide… | |
| Modificada | Media (5.3) | 0.28% | — | Jenkins Sensedia API Platform Tools | 9/7/2025 | 17/6/2026 | Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to observe and capture it. | |
| Modificada | Media (6.5) | 0.22% | — | Jenkins Sensedia API Platform Tools | 9/7/2025 | 17/6/2026 | Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system. | |
| Aplazada | Alta (7.5) | 0.60% | — | Api-platform API Platform CoreAI | 3/4/2025 | 17/6/2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL grant on a property might be cached with different objects. The ApiPlatform\GraphQl\Serializer\ItemNormalizer::isCacheKeySafe() method is meant to prevent the caching but the parent::normalize method… | |
| Aplazada | Alta (7.5) | 0.46% | — | Api-platform CoreAI | 3/4/2025 | 17/6/2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17. | |
| Aplazada | Media (5.3) | 0.37% | — | Api-platform API Platform CoreAI | 3/4/2025 | 17/6/2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messages, that are not HTTP exceptions, are visible in the JSON error response. This vulnerability is fixed in 3.2.5. | |
| Aplazada | Media (4.4) | 0.29% | — | Api-platform CoreAI | 24/3/2025 | 17/6/2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls back to `security`, the impact is there only when there's only a… | |
| Aplazada | Crítica (9.3) | 0.44% | — | Akana API PlatformAI | 18/4/2024 | 17/6/2026 | A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson. | |
| Modificada | Media (6.5) | 0.60% | — | Api-platform Core | 28/2/2023 | 17/6/2026 | API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the `ApiPlatform\Metadata\ApiProperty` attribute can be disclosed to unauthorized users. The problem affects most serialization formats, including raw JSON, which is enabled… | |
| Modificada | Media (6.5) | 1.0% | — | Api-platform Core | 4/2/2019 | 17/6/2026 | API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitable via the user must be authorized. This vulnerability appears to have been fixed… |