Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.2) | 0.30% | — | SqlalchemyAI | 26/8/2026 | 1/9/2026 | The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no join between them. SQLAlchemy resolves that as an implicit cross join, so the filter does not constrain the delete to the calling user's own token in the way the code reads as intending. This way a… | |
| Pendiente de análisis | Alta (8.3) | 0.38% | — | Snowflake SqlalchemyAI | 14/7/2026 | 15/7/2026 | Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. An attacker may be able to exploit this through request field names in a dynamic… | |
| Aplazada | Alta (7.1) | 0.38% | — | Dfir-irisAIGrapheneAIGraphene-sqlalchemyAIPalletsprojects FlaskAI | 4/6/2026 | 22/7/2026 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to version 2.4.28, DFIR-IRIS exposes an optional GraphQL endpoint at `/graphql` that does not enforce the same authorization checks as the REST API. Any authenticated user can abuse it in three… | |
| Modificada | Alta (7.7) | 0.53% | — | Sqlalchemy Mako | 23/4/2026 | 17/6/2026 | Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as… | |
| Aplazada | Baja (3.7) | 0.38% | — | DjangoAISqlalchemyAIPydanticAIStrawberry GraphqlAI | 9/1/2025 | 17/6/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability occurs when multiple GraphQL types are… | |
| Modificada | Crítica (9.8) | 0.89% | — | Zope Sqlalchemyda | 7/2/2024 | 17/6/2026 | SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2. There is no… | |
| Modificada | Alta (7.5) | 2.2% | — | Sqlalchemy MakoDebian Linux | 7/9/2022 | 17/6/2026 | Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin. | |
| Modificada | Crítica (9.8) | 3.5% | — | SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+5 | 20/2/2019 | 17/6/2026 | SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. | |
| Modificada | Alta (7.8) | 1.8% | — | SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+5 | 6/2/2019 | 17/6/2026 | SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. | |
| Modificada | Alta (7.5) | 2.9% | — | Sqlalchemy | 5/6/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function. |