Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
–

924 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.4)——Graphql ToolsAI1/10/20261/10/2026
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with…
Pendiente de análisisMedia (5.3)0.51%—GraphicsmagickAI30/9/202630/9/2026
A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2.…
Pendiente de análisisMedia (5.4)0.27%—WpgraphqlAI23/9/202623/9/2026
WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status…
AplazadaMedia (6.5)0.34%—Wpgraphql Smart CacheAI19/9/202621/9/2026
The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them.
AplazadaAlta (8.8)0.49%—Yeger Turbo-graphAIYeger Turbo-graph-uiAI15/9/202630/9/2026
Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in…
AplazadaAlta (8.7)0.48%—LokkaAIMicrosoft 365AIMicrosoft GraphAIMicrosoft Azure Resource ManagerAI15/9/202630/9/2026
Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can…
Pendiente de análisisAlta (7.7)0.53%—Langchain Langgraph-checkpoint-mongodbAILangchain Langgraph-store-mongodbAI14/9/202630/9/2026
LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively…
AplazadaMedia (5.9)0.26%—Langchain Langgraph-apiAI14/9/202630/9/2026
langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-creation path authorizes the assistant attached to a run by dispatching assistants.search with an incomplete value instead of the assistants.read event used by direct reads and cron creation. In…
AplazadaMedia (5.9)0.36%—Langchain Langgraph-apiAI14/9/202630/9/2026
langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is delivered through an in-process loopback transport, and the authentication middleware treats that transport as internal without applying the…
AplazadaMedia (6.9)0.69%—Getzep GraphitiAI13/9/202615/9/2026
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
AplazadaMedia (6.9)0.58%—Embedded-graphicsAI13/9/202615/9/2026
A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project…
AplazadaMedia (6.9)0.52%—Embedded-graphicsAI13/9/202616/9/2026
A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through…
AplazadaAlta (7.2)0.37%—Gpx2graphicsAI12/9/202614/9/2026
The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
AplazadaAlta (8.8)0.42%—Gato GraphqlAI11/9/202611/9/2026
Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
AplazadaMedia (6.4)0.19%—GraphinaAI9/9/20269/9/2026
The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
En análisisAlta (8.8)0.84%—Microsoft Graphics ComponentAI8/9/202624/9/2026
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
En análisisAlta (8.8)0.84%—Microsoft Graphics ComponentAI8/9/202617/9/2026
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
AplazadaMedia (6.5)0.22%—GrapheneAI3/9/20265/9/2026
Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.
Pendiente de análisisAlta (7.5)0.61%—Smallrye GraphqlAI31/8/20261/9/2026
A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a large exponent float literal. This can lead to the allocation of extremely…
AplazadaBaja (2.3)0.39%—Ash-project ASH GraphqlAI30/8/20261/9/2026
Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolved records to a different subscriber's topic. AshGraphql.Subscription.Batcher.do_send/5 reads the resolved batch from the process dictionary via Process.get(:batch_resolved) and then unconditionally…
AplazadaBaja (2.3)0.43%—Ash-project ASH GraphqlAI30/8/20261/9/2026
Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see. In AshGraphql.Subscription.Batcher, do_send/5 resolves the first notification of a batch and filters it with should_send?/1, which drops results whose errors are…
AplazadaAlta (8.7)0.55%—Ash-project ASH GraphqlAI30/8/20261/9/2026
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an unbounded database read. AshGraphql.Graphql.Resolver.query_complexity/3 multiplies child complexity by the requested page…
AplazadaMedia (6.9)0.52%—Ash-project ASH GraphqlAI30/8/20261/9/2026
Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id: ...) query with an unhandled KeyError. AshGraphql.Graphql.Resolver.resolve_node/2 decodes the client-supplied global ID with decode_relay_id/1, which only base64-decodes the string and splits…
AplazadaAlta (7.1)0.43%—Ash-project ASH GraphqlAI30/8/20263/9/2026
Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in AshGraphql.Graphql.Resolver authorizes each notification payload in memory: its fast path calls Ash.can/3 with…
AplazadaMedia (6.9)0.52%—Ash-project ASH GraphqlAI30/8/20261/9/2026
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote client to read internal field names that an application configured its error_handler to redact. In AshGraphql.Errors, each error is passed to the configured error_handler and the returned map is merged…