| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-35577 | Missing Host Header Validation in Apollo MCP Server for Localhost Deployments | apollographql | apollo-mcp-server | Medium | 6.8 | 2026-04-09 19:40:26 | Deep Dive |
| CVE-2026-32621 | Apollo Federation has prototype pollution via incomplete key sanitization | @apollo | federation-internals | Critical | 9.9 | 2026-03-13 20:29:55 | Deep Dive |
| CVE-2026-27340 | WordPress Apollo | Night Club, DJ Event WordPress Theme theme <= 1.3.1 - Local File Inclusion vulnerability | AncoraThemes | Apollo | Night Club, DJ Event WordPress Theme | 中危 | - | 2026-03-05 05:53:52 | Deep Dive |
| CVE-2026-23897 | Apollo Server is vulnerable to denial of service with `startStandaloneServer` | apollographql | apollo-server | High | 7.5 | 2026-02-04 19:19:00 | Deep Dive |
| CVE-2025-48168 | WordPress Apollo - Sticky Full Width HTML5 Audio Player <= 3.4 - Cross Site Scripting (XSS) Vulnerability | LambertGroup | Apollo - Sticky Full Width HTML5 Audio Player | High | 7.1 | 2025-08-20 08:03:27 | Deep Dive |
| CVE-2024-6648 | Path Traversal in AP Page Builder | Apollo Theme | AP Page Builder | - | - | 2025-05-08 12:16:53 | Deep Dive |
| CVE-2025-23181 | Ribbon Communications - CWE-250: Execution with Unnecessary Privileges | Ribbon Communications | Apollo 9608 | High | 8.0 | 2025-04-29 16:19:37 | Deep Dive |
| CVE-2025-23180 | Ribbon Communications - CWE-250: Execution with Unnecessary Privileges | Ribbon Communications | Apollo 9608 | High | 8.0 | 2025-04-29 16:18:48 | Deep Dive |
| CVE-2025-23179 | Ribbon Communications - CWE-798: Use of Hard-coded Credentials | Ribbon Communications | Apollo 9608 | Medium | 5.5 | 2025-04-29 16:09:12 | Deep Dive |
| CVE-2025-23178 | Ribbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended Endpoints | Ribbon Communications | Apollo 9608 | High | 7.6 | 2025-04-29 16:05:06 | Deep Dive |
| CVE-2025-23177 | Ribbon Communications - CWE-427: Uncontrolled Search Path Element | Ribbon Communications | Apollo 9608 | High | 7.6 | 2025-04-29 16:01:41 | Deep Dive |
| CVE-2025-31496 | apollo-compiler Named Fragment Processing Vulnerability | apollographql | apollo-rs | High | 7.5 | 2025-04-07 20:34:47 | Deep Dive |
| CVE-2025-20002 | GMOD Apollo Generation of Error Message Containing Sensitive Information | GMOD | Apollo | Medium | 5.3 | 2025-03-05 00:08:14 | Deep Dive |
| CVE-2025-24924 | GMOD Apollo Missing Authentication for Critical Function | GMOD | Apollo | Critical | 9.8 | 2025-03-05 00:02:08 | Deep Dive |
| CVE-2025-23410 | GMOD Apollo Relative Path Traversal | GMOD | Apollo | Critical | 9.8 | 2025-03-04 23:58:52 | Deep Dive |
| CVE-2025-21092 | GMOD Apollo Incorrect Privilege Assignment | GMOD | Apollo | Medium | 6.5 | 2025-03-04 23:49:12 | Deep Dive |
| CVE-2024-43397 | Potential unauthorized access issue in apollo-portal | apolloconfig | apollo | Medium | 4.3 | 2024-08-20 14:50:01 | Deep Dive |
| CVE-2024-23841 | XSS in @apollo/experimental-nextjs-app-support | apollographql | apollo-client-nextjs | High | 8.2 | 2024-01-30 17:14:12 | Deep Dive |
| CVE-2022-4962 | Apollo Configuration Center users improper authorization | - | Apollo | Medium | 4.3 | 2024-01-12 22:00:04 | Deep Dive |
| CVE-2023-30959 | Stored XSS via javascript URI in Apollo Change Requests comment | Palantir | com.palantir.apollo:autopilot | Medium | 4.1 | 2023-09-26 17:56:21 | Deep Dive |