Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the confsrv set_port_fwd_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.3% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the confsrv confctl_set_app_language functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.96% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root password. An attacker does not have to do anything to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 3.7% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.89% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the confers ucloud_add_node_new functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 3.7% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 1.1% | — | Admesh Project AdmeshDebian Linux | 8/5/2022 | 17/6/2026 | ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a. | |
| Modificada | Media (6.5) | 0.34% | — | F5 Nginx Service Mesh | 5/5/2022 | 17/6/2026 | On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Modificada | Media (4.8) | 0.56% | — | Mythemeshop WP Subscribe | 2/5/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress. | |
| Modificada | Media (6.5) | 0.98% | — | Libmeshb Project Libmeshb | 12/1/2022 | 17/6/2026 | A buffer overflow in the GmfOpenMesh() function of libMeshb v7.61 allows attackers to cause a Denial of Service (DoS) via a crafted MESH file. | |
| Modificada | Media (6.1) | 0.77% | — | Cisco Collaboration Meeting RoomsCisco Webex Video Mesh | 4/11/2021 | 17/6/2026 | A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this… | |
| Modificada | Media (6.1) | 0.81% | — | Cisco Collaboration Meeting RoomsCisco Webex Video Mesh | 4/11/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (8.8) | 0.97% | — | Netlify Kiali-operatorRedhat Openshift Service Mesh | 1/6/2021 | 17/6/2026 | An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability and deploy a given image to anywhere in the cluster, potentially gaining access to… | |
| Modificada | Alta (8.1) | 0.85% | — | Bluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey. | |
| Modificada | Alta (8.8) | 0.85% | — | Bluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device… | |
| Modificada | Alta (7.5) | 0.83% | — | Bluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time). | |
| Modificada | Alta (7.5) | 0.91% | — | Bluetooth Core SpecificationBluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment. | |
| Modificada | Media (5.4) | 0.66% | — | Livemeshelementor Addons FOR Elementor | 5/5/2021 | 17/6/2026 | The “Livemesh Addons for Elementor” WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Layer5 Meshery | 28/4/2021 | 17/6/2026 | A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go). | |
| Modificada | Media (6.5) | 1.3% | — | IstioRedhat Openshift Service Mesh | 29/1/2021 | 17/6/2026 | A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is possible to cause the Go runtime to panic (resulting in a denial of service to the istio-pilot application). | |
| Modificada | Crítica (9.8) | 4.9% | — | GrafanaSaml Project SamlRedhat Openshift Container PlatformRedhat Openshift Service Mesh+2 | 21/12/2020 | 17/6/2026 | A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. | |
| Modificada | Alta (7.5) | 1.0% | — | UI Unifi Meshing Access Point FirmwareUI Unifi Controller Firmware | 27/10/2020 | 17/6/2026 | An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected state. This may provide unintended network access. | |
| Modificada | Alta (8.6) | 1.2% | — | KialiRedhat Openshift Service Mesh | 27/4/2020 | 17/6/2026 | An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration. | |
| Modificada | Alta (8.6) | 3.5% | 💥 PoC | KialiRedhat Openshift Service Mesh | 26/3/2020 | 17/6/2026 | A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio… | |
| Modificada | Alta (7) | 0.28% | — | Timeshift Project TimeshiftFedoraproject FedoraCanonical Ubuntu Linux | 5/3/2020 | 17/6/2026 | init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses directories owned by unprivileged users. Because Timeshift also executes scripts under this location, an attacker can… |