Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A stack-based buffer overflow vulnerability exists in the confsrv set_port_fwd_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.3%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A stack-based buffer overflow vulnerability exists in the confsrv confctl_set_app_language functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)0.96%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root password. An attacker does not have to do anything to trigger this vulnerability.
ModificadaCrítica (9.8)3.7%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaAlta (8.8)0.89%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A stack-based buffer overflow vulnerability exists in the confers ucloud_add_node_new functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)3.7%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaAlta (8.1)1.1%—Admesh Project AdmeshDebian Linux8/5/202217/6/2026
ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a.
ModificadaMedia (6.5)0.34%—F5 Nginx Service Mesh5/5/202217/6/2026
On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
ModificadaMedia (4.8)0.56%—Mythemeshop WP Subscribe2/5/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress.
ModificadaMedia (6.5)0.98%—Libmeshb Project Libmeshb12/1/202217/6/2026
A buffer overflow in the GmfOpenMesh() function of libMeshb v7.61 allows attackers to cause a Denial of Service (DoS) via a crafted MESH file.
ModificadaMedia (6.1)0.77%—Cisco Collaboration Meeting RoomsCisco Webex Video Mesh4/11/202117/6/2026
A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this…
ModificadaMedia (6.1)0.81%—Cisco Collaboration Meeting RoomsCisco Webex Video Mesh4/11/202117/6/2026
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request. An attacker could exploit this vulnerability by…
ModificadaAlta (8.8)0.97%—Netlify Kiali-operatorRedhat Openshift Service Mesh1/6/202117/6/2026
An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability and deploy a given image to anywhere in the cluster, potentially gaining access to…
ModificadaAlta (8.1)0.85%—Bluetooth Mesh Profile24/5/202117/6/2026
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey.
ModificadaAlta (8.8)0.85%—Bluetooth Mesh Profile24/5/202117/6/2026
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device…
ModificadaAlta (7.5)0.83%—Bluetooth Mesh Profile24/5/202117/6/2026
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time).
ModificadaAlta (7.5)0.91%—Bluetooth Core SpecificationBluetooth Mesh Profile24/5/202117/6/2026
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment.
ModificadaMedia (5.4)0.66%—Livemeshelementor Addons FOR Elementor5/5/202117/6/2026
The “Livemesh Addons for Elementor” WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
ModificadaCrítica (9.8)75%💥 ExploitLayer5 Meshery28/4/202117/6/2026
A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).
ModificadaMedia (6.5)1.3%—IstioRedhat Openshift Service Mesh29/1/202117/6/2026
A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is possible to cause the Go runtime to panic (resulting in a denial of service to the istio-pilot application).
ModificadaCrítica (9.8)4.9%—GrafanaSaml Project SamlRedhat Openshift Container PlatformRedhat Openshift Service Mesh+221/12/202017/6/2026
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
ModificadaAlta (7.5)1.0%—UI Unifi Meshing Access Point FirmwareUI Unifi Controller Firmware27/10/202017/6/2026
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected state. This may provide unintended network access.
ModificadaAlta (8.6)1.2%—KialiRedhat Openshift Service Mesh27/4/202017/6/2026
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
ModificadaAlta (8.6)3.5%💥 PoCKialiRedhat Openshift Service Mesh26/3/202017/6/2026
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio…
ModificadaAlta (7)0.28%—Timeshift Project TimeshiftFedoraproject FedoraCanonical Ubuntu Linux5/3/202017/6/2026
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses directories owned by unprivileged users. Because Timeshift also executes scripts under this location, an attacker can…
Orbitaley — Vulnerabilidades