Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 1.8% | — | MeshtasticAI | 20/7/2026 | 24/7/2026 | Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN… | |
| Analizada | Alta (7.5) | 0.49% | — | Meshtastic Firmware | 20/7/2026 | 18/8/2026 | Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. The malformed name does not need to be maliciously crafted — it can… | |
| Aplazada | Media (5.1) | 0.14% | — | FlameshotAI | 15/7/2026 | 15/7/2026 | Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause… | |
| Aplazada | Media (6.5) | 0.22% | — | Livemesh Addons FOR Wpbakery Page BuilderAI | 2/7/2026 | 2/7/2026 | Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions. | |
| Aplazada | Crítica (9.2) | 0.81% | — | Netcomm Nf20meshAI | 23/6/2026 | 23/6/2026 | NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge a valid encrypted… | |
| Aplazada | Alta (8.7) | 1.3% | — | Netcomm Nf20meshAI | 23/6/2026 | 24/6/2026 | NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands as root by injecting shell metacharacters into the username JSON parameter processed by the dalStorage_addUserAccount function.… | |
| Analizada | Alta (7.5) | 1.1% | — | Envoyproxy EnvoyRedhat Openshift Service Mesh | 17/6/2026 | 20/7/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consumption, potentially resulting in OOM… | |
| Modificada | Alta (7.7) | 1.0% | — | AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+8 | 11/6/2026 | 11/9/2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions… | |
| Analizada | Crítica (9.6) | 0.48% | — | Jpettitt Meshcore Card | 28/5/2026 | 17/6/2026 | MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary javascript in the Home Assistant frontend of anyone viewing the card. This… | |
| Aplazada | Media (6.4) | 0.30% | — | Livemesh Addons FOR Beaver BuilderAI | 27/5/2026 | 17/6/2026 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user… | |
| Aplazada | Media (6.4) | 0.30% | — | Livemesh Siteorigin WidgetsAI | 27/5/2026 | 17/6/2026 | The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user… | |
| Aplazada | Media (6.4) | 0.30% | — | Livemesh Wpbakery Page Builder AddonsAI | 27/5/2026 | 17/6/2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check… | |
| Aplazada | Media (6.4) | 0.24% | — | Livemesh Wpbakery Page Builder AddonsAI | 27/5/2026 | 17/6/2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[lvca_carousel]` and `[lvca_posts_carousel]` shortcode attributes in all versions up to, and including, 3.9.4 due to insufficient input sanitization and output escaping. Specifically, shortcode… | |
| Aplazada | Alta (8.8) | 0.82% | — | Livemesh Addons FOR ElementorAI | 16/4/2026 | 17/6/2026 | The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due to insufficient sanitization of the template name parameter in the `lae_get_template_part()` function, which uses an inadequate `str_replace()` approach that can be… | |
| Aplazada | Media (6.4) | 0.32% | — | Livemesh Addons FOR ElementorAI | 16/4/2026 | 17/6/2026 | The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 9.0. This is due to missing authorization checks on the AJAX handler `lae_admin_ajax()` and insufficient output escaping on… | |
| Aplazada | Media (6.5) | 0.22% | 💥 PoC | Livemesh Addons FOR ElementorAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Stored XSS.This issue affects Livemesh Addons for Elementor: from n/a through <= 9.0. | |
| Analizada | Crítica (9.9) | 0.99% | 💥 PoC | Intermesh Group-office | 2/4/2026 | 24/7/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object into a setting… | |
| Analizada | Alta (8.8) | 0.46% | — | Intermesh Group-office | 27/3/2026 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in the JMAP `Contact/query` endpoint allows any authenticated user with basic addressbook access to extract arbitrary data from the database —… | |
| Analizada | Media (5.1) | 0.33% | — | Intermesh Group-office | 6/3/2026 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, and 26.0.10, there is a reflected XSS vulnerability in GroupOffice on the external/index flow. The f parameter (Base64 JSON) is decoded and then injected into an inline JavaScript block without strict… | |
| Analizada | Baja (2.1) | 0.27% | — | Intermesh Group-office | 6/3/2026 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, and 26.0.10, there is a reflected XSS vulnerability in the GroupOffice installer, endpoint install/license.php. The POST field license is rendered without escaping inside a <textarea>, allowing a… | |
| Analizada | Crítica (9.4) | 1.0% | — | Intermesh Group-office | 27/2/2026 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticated Remote Code Execution vulnerability in the TNEF attachment processing flow. The vulnerable path extracts attacker-controlled files from `winmail.dat` and then invokes… | |
| Analizada | Alta (7.1) | 0.46% | — | Intermesh Group-office | 27/2/2026 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, and 6.8.153 have a SQL Injection (SQLi) vulnerability, exploitable through the `advancedQueryData` parameter (`comparator` field) on an authenticated endpoint. The endpoint… | |
| Aplazada | Media (6.4) | 0.19% | — | Livemesh Addons FOR Beaver BuilderAI | 26/2/2026 | 17/6/2026 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_pricing_item]` shortcode's `title` and `value` attributes in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. Specifically, the plugin uses… | |
| Analizada | Baja (1.9) | 0.23% | — | Admesh Project Admesh | 18/2/2026 | 17/6/2026 | A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used… | |
| Analizada | Alta (8.2) | 0.15% | — | Meshtastic Firmware | 28/1/2026 | 17/6/2026 | Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, rather than their public key. This aspect downgrades the security, specifically by abusing the HAM mode which doesn't use encryption. An attacker can, as… |