Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (1.2)0.30%—SqlalchemyAI26/8/20261/9/2026
The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no join between them. SQLAlchemy resolves that as an implicit cross join, so the filter does not constrain the delete to the calling user's own token in the way the code reads as intending. This way a…
Pendiente de análisisAlta (8.3)0.38%—Snowflake SqlalchemyAI14/7/202615/7/2026
Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. An attacker may be able to exploit this through request field names in a dynamic…
AplazadaAlta (7.1)0.38%—Dfir-irisAIGrapheneAIGraphene-sqlalchemyAIPalletsprojects FlaskAI4/6/202622/7/2026
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to version 2.4.28, DFIR-IRIS exposes an optional GraphQL endpoint at `/graphql` that does not enforce the same authorization checks as the REST API. Any authenticated user can abuse it in three…
ModificadaAlta (7.7)0.53%—Sqlalchemy Mako23/4/202617/6/2026
Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as…
AplazadaBaja (3.7)0.38%—DjangoAISqlalchemyAIPydanticAIStrawberry GraphqlAI9/1/202517/6/2026
Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability occurs when multiple GraphQL types are…
ModificadaCrítica (9.8)0.89%—Zope Sqlalchemyda7/2/202417/6/2026
SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2. There is no…
ModificadaAlta (7.5)2.2%—Sqlalchemy MakoDebian Linux7/9/202217/6/2026
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
ModificadaCrítica (9.8)3.5%—SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+520/2/201917/6/2026
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
ModificadaAlta (7.8)1.8%—SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+56/2/201917/6/2026
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
ModificadaAlta (7.5)2.9%—Sqlalchemy5/6/201216/6/2026
Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.