Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
924 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.4) | — | — | Graphql ToolsAI | 1/10/2026 | 1/10/2026 | GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with… | |
| Pendiente de análisis | Media (5.3) | 0.51% | — | GraphicsmagickAI | 30/9/2026 | 30/9/2026 | A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2.… | |
| Pendiente de análisis | Media (5.4) | 0.27% | — | WpgraphqlAI | 23/9/2026 | 23/9/2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status… | |
| Aplazada | Media (6.5) | 0.34% | — | Wpgraphql Smart CacheAI | 19/9/2026 | 21/9/2026 | The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them. | |
| Aplazada | Alta (8.8) | 0.49% | — | Yeger Turbo-graphAIYeger Turbo-graph-uiAI | 15/9/2026 | 30/9/2026 | Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in… | |
| Aplazada | Alta (8.7) | 0.48% | — | LokkaAIMicrosoft 365AIMicrosoft GraphAIMicrosoft Azure Resource ManagerAI | 15/9/2026 | 30/9/2026 | Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can… | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Langchain Langgraph-checkpoint-mongodbAILangchain Langgraph-store-mongodbAI | 14/9/2026 | 30/9/2026 | LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively… | |
| Aplazada | Media (5.9) | 0.26% | — | Langchain Langgraph-apiAI | 14/9/2026 | 30/9/2026 | langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-creation path authorizes the assistant attached to a run by dispatching assistants.search with an incomplete value instead of the assistants.read event used by direct reads and cron creation. In… | |
| Aplazada | Media (5.9) | 0.36% | — | Langchain Langgraph-apiAI | 14/9/2026 | 30/9/2026 | langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is delivered through an in-process loopback transport, and the authentication middleware treats that transport as internal without applying the… | |
| Aplazada | Media (6.9) | 0.69% | — | Getzep GraphitiAI | 13/9/2026 | 15/9/2026 | A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance. | |
| Aplazada | Media (6.9) | 0.58% | — | Embedded-graphicsAI | 13/9/2026 | 15/9/2026 | A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project… | |
| Aplazada | Media (6.9) | 0.52% | — | Embedded-graphicsAI | 13/9/2026 | 16/9/2026 | A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through… | |
| Aplazada | Alta (7.2) | 0.37% | — | Gpx2graphicsAI | 12/9/2026 | 14/9/2026 | The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution. | |
| Aplazada | Alta (8.8) | 0.42% | — | Gato GraphqlAI | 11/9/2026 | 11/9/2026 | Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions. | |
| Aplazada | Media (6.4) | 0.19% | — | GraphinaAI | 9/9/2026 | 9/9/2026 | The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| En análisis | Alta (8.8) | 0.84% | — | Microsoft Graphics ComponentAI | 8/9/2026 | 24/9/2026 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | |
| En análisis | Alta (8.8) | 0.84% | — | Microsoft Graphics ComponentAI | 8/9/2026 | 17/9/2026 | Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (6.5) | 0.22% | — | GrapheneAI | 3/9/2026 | 5/9/2026 | Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | Smallrye GraphqlAI | 31/8/2026 | 1/9/2026 | A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a large exponent float literal. This can lead to the allocation of extremely… | |
| Aplazada | Baja (2.3) | 0.39% | — | Ash-project ASH GraphqlAI | 30/8/2026 | 1/9/2026 | Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolved records to a different subscriber's topic. AshGraphql.Subscription.Batcher.do_send/5 reads the resolved batch from the process dictionary via Process.get(:batch_resolved) and then unconditionally… | |
| Aplazada | Baja (2.3) | 0.43% | — | Ash-project ASH GraphqlAI | 30/8/2026 | 1/9/2026 | Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see. In AshGraphql.Subscription.Batcher, do_send/5 resolves the first notification of a batch and filters it with should_send?/1, which drops results whose errors are… | |
| Aplazada | Alta (8.7) | 0.55% | — | Ash-project ASH GraphqlAI | 30/8/2026 | 1/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an unbounded database read. AshGraphql.Graphql.Resolver.query_complexity/3 multiplies child complexity by the requested page… | |
| Aplazada | Media (6.9) | 0.52% | — | Ash-project ASH GraphqlAI | 30/8/2026 | 1/9/2026 | Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id: ...) query with an unhandled KeyError. AshGraphql.Graphql.Resolver.resolve_node/2 decodes the client-supplied global ID with decode_relay_id/1, which only base64-decodes the string and splits… | |
| Aplazada | Alta (7.1) | 0.43% | — | Ash-project ASH GraphqlAI | 30/8/2026 | 3/9/2026 | Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in AshGraphql.Graphql.Resolver authorizes each notification payload in memory: its fast path calls Ash.can/3 with… | |
| Aplazada | Media (6.9) | 0.52% | — | Ash-project ASH GraphqlAI | 30/8/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote client to read internal field names that an application configured its error_handler to redact. In AshGraphql.Errors, each error is passed to the configured error_handler and the returned map is merged… |