Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

670 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.6)0.14%—Meatmeet10/12/202517/6/2026
The mobile application insecurely handles information stored within memory. By performing a memory dump on the application after a user has logged out and terminated it, Wi-Fi credentials sent during the pairing process, JWTs used for authentication, and other sensitive details can be retrieved. As a result, an…
AnalizadaAlta (7.5)0.21%—Meatmeet10/12/202517/6/2026
The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hashes, either through exploiting cloud services, performing TLS downgrade attacks on the traffic from a mobile device, or through another means, they may be able to crack the hash in a reasonable amount…
AnalizadaCrítica (9.1)0.27%—Meatmeet10/12/202517/6/2026
Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstream" can decrypt the TLS traffic, inspect its contents, and modify the requests in transit. This may result in a total compromise of the user's account if the attacker intercepts…
AnalizadaMedia (6.8)0.32%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202517/6/2026
The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that only authenticated software can execute on the device. The Secure Boot process forms a chain of trust by verifying all mutable software entities involved in the Application…
AnalizadaCrítica (9.1)0.26%—Meatmeet10/12/202517/6/2026
The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can intercept the traffic, inspect its contents, and modify the requests in transit. TThis may result in a total compromise of the user's account…
AnalizadaCrítica (9.8)0.29%—Meatmeet10/12/202517/6/2026
The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain unauthorized access to the Wi-Fi network of the vendor. Additionally, if an attacker were located in close physical…
AnalizadaMedia (4.6)0.13%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202517/6/2026
The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble the device, connect over UART, and retrieve the firmware dump for analysis. Within the NVS partition they may discover the credentials of the current and previous Wi-Fi networks.…
AnalizadaMedia (6.8)0.21%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202517/6/2026
The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commercial product an attacker with physical access to the device can connect over this port and reflash the device's firmware with malicious code which will be executed upon running.…
AnalizadaAlta (7.5)0.37%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202517/6/2026
As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the current and previous Wi-Fi network from the NVS partition. Additionally, this allows the adversary to reflash the device with…
AnalizadaCrítica (9.8)0.47%—Meatmeet10/12/202517/6/2026
An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mobile application which opens a hidden page. This page, which is not available through the normal flows of the application, contains several devices which can be added to your account, two of which…
ModificadaMedia (6.5)0.28%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202525/9/2026
An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which would result in a Denial of Service. These commands include: shutdown, restart, clear config. Clear config would disassociate the current device from its user and would…
AnalizadaAlta (8.8)0.56%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202525/9/2026
An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy (BLE), resulting in the firmware on the device being overwritten with the attacker's code. As the device does not perform checks on upgrades, this results in…
AnalizadaCrítica (9.8)0.43%—Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware10/12/202528/9/2026
The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain unauthorized access to the Wi-Fi network of the vendor. Additionally, if an attacker…
AplazadaAlta (8.8)0.12%—MeetmeAI2/12/202517/6/2026
Insecure Storage of Sensitive Information vulnerability in MeetMe on iOS, Android allows Retrieve Embedded Sensitive Data. This issue affects MeetMe: through v2.2.5.
AplazadaBaja (2.7)0.49%—Jitsi MeetAI13/11/202517/6/2026
Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for Microsoft accounts. This is fixed in version 2.0.10532. No known workarounds are available.
AnalizadaCrítica (9.8)0.30%—Zoom Meeting Software Development KITZoom Workplace13/11/202517/6/2026
Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
AnalizadaCrítica (9.8)0.42%—Zoom Meeting Software Development KITZoom Workplace13/11/202517/6/2026
Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (7.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+113/11/202517/6/2026
External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaMedia (5.5)0.15%—Zoom Meeting Software Development KITZoom Workplace Desktop13/11/202517/6/2026
External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access.
AnalizadaAlta (7.5)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+113/11/202517/6/2026
Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaMedia (6.1)0.19%—Zoom Meeting Software Development KITZoom Workplace Desktop13/11/202517/6/2026
Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.
AnalizadaMedia (6.5)0.10%—Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure13/11/202517/6/2026
Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.
AplazadaMedia (6.5)0.31%—Sovlix MeetinghubAI6/11/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Sovlix MeetingHub meetinghub allows Retrieve Embedded Sensitive Data.This issue affects MeetingHub: from n/a through <= 1.23.9.
AplazadaMedia (4.4)0.21%—MeetinglistAI4/11/202517/6/2026
The MeetingList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
AplazadaMedia (4.3)0.20%—Sovlix MeetinghubAI22/10/202517/6/2026
Missing Authorization vulnerability in Sovlix MeetingHub meetinghub.This issue affects MeetingHub: from n/a through <= 1.23.9.
Orbitaley — Vulnerabilidades