Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.26% | — | Meshtastic AndroidAI | 24/6/2025 | 17/6/2026 | Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacker is able to send an unencrypted direct message to a victim impersonating any other node of the mesh. This message will be displayed in the same chat that the victim normally communicates with the… | |
| Analizada | Crítica (9.5) | 0.58% | 💥 PoC | Meshtastic Firmware | 19/6/2025 | 17/6/2026 | Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resulting in duplicated public/private keys. Additionally, the Meshtastic was failing to properly initialize the internal randomness pool on some platforms, leading to… | |
| Analizada | Media (5.3) | 0.25% | — | Intermesh Group-office | 17/6/2025 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a malicious JavaScript payload can be executed via the Look and Feel formatting fields. Any user can update their Look and Feel Formatting input fields, but the web application does not sanitize… | |
| Analizada | Media (5.2) | 0.26% | — | Intermesh Group-office | 16/6/2025 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a stored and blind cross-site scripting (XSS) vulnerability exists in the Name Field of the user profile. A malicious attacker can change their name to a javascript payload, which is executed when… | |
| Analizada | Media (5.3) | 0.26% | — | Intermesh Group-office | 22/5/2025 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a persistent Cross-Site Scripting (XSS) vulnerability exists in Groupoffice's tasks comment functionality, allowing attackers to execute arbitrary JavaScript by uploading an file with a crafted… | |
| Analizada | Media (5.8) | 0.26% | — | Intermesh Group-office | 22/5/2025 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a DOM-based Cross-Site Scripting (XSS) vulnerability exists in the GroupOffice application, allowing attackers to execute arbitrary JavaScript code in the context of the victim's browser. This can… | |
| Analizada | Media (6.9) | 0.27% | — | Intermesh Group-office | 22/5/2025 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a stored and blind XSS vulnerability exists in the Phone Number field of the user profile within the GroupOffice application. This allows a malicious actor to inject persistent JavaScript payloads,… | |
| Analizada | Media (6.5) | 0.13% | — | Gotenna Mesh FirmwareGotenna | 1/5/2025 | 17/6/2026 | An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. | |
| Analizada | Alta (8.8) | 0.19% | — | Gotenna Mesh FirmwareGotenna | 1/5/2025 | 17/6/2026 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna server is hardcoded in the app. | |
| Analizada | Alta (8.8) | 0.19% | — | Gotenna Mesh FirmwareGotenna | 1/5/2025 | 17/6/2026 | An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna server is hardcoded in the app. | |
| Analizada | Media (6.5) | 0.17% | — | Gotenna Mesh FirmwareGotenna | 1/5/2025 | 17/6/2026 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be intercepted and used to break frequency hopping. | |
| Analizada | Media (5.5) | 0.15% | — | Gotenna Mesh FirmwareGotenna | 1/5/2025 | 17/6/2026 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent over UART with USB Shell, allowing someone with local access to gain information about the protocol and intercept sensitive data. | |
| Analizada | Media (6.5) | 0.23% | — | Gotenna Mesh FirmwareGotenna | 1/5/2025 | 17/6/2026 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom message (into existing v1 networks) with any GID and Callsign via a software defined radio. This can be exploited if the device is being used in an unencrypted environment or if the… | |
| Analizada | Media (6.5) | 0.16% | — | Gotenna Mesh FirmwareGotenna | 1/5/2025 | 17/6/2026 | An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages. | |
| Analizada | Media (6.5) | 0.09% | — | Gotenna Mesh FirmwareGotenna | 1/5/2025 | 17/6/2026 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. | |
| Analizada | Media (6.5) | 0.16% | — | Gotenna Mesh FirmwareGotenna | 1/5/2025 | 17/6/2026 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages. | |
| Aplazada | Media (6.5) | 0.22% | — | Mythemeshop WP QuizAI | 25/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz wp-quiz allows Stored XSS.This issue affects WP Quiz: from n/a through <= 2.0.10. | |
| Analizada | Crítica (9.8) | 0.88% | 💥 PoC | Meshtastic Firmware | 15/4/2025 | 17/6/2026 | Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow, allowing an attacker to hijack execution flow, potentially resulting in remote code execution. This attack does not require… | |
| Aplazada | Media (4.3) | 0.19% | — | Animesh Kumar Advanced Speed IncreaserAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Animesh Kumar Advanced Speed Increaser advanced-speed-increaser.This issue affects Advanced Speed Increaser: from n/a through <= 2.2.1. | |
| Aplazada | Media (6.4) | 0.25% | — | Livemesh Elementor AddonsAI | 1/4/2025 | 17/6/2026 | The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Cursor Extension in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.36% | — | Umesh Ghimire Frontend Post SubmissionAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Umesh Ghimire Frontend Post Submission frontend-post-submission allows Reflected XSS.This issue affects Frontend Post Submission: from n/a through <= 1.0. | |
| Analizada | Alta (7.5) | 0.36% | — | The-guild Graphql Mesh CLIThe-guild Graphql Mesh Http | 20/2/2025 | 17/6/2026 | GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. Missing check vulnerability in the static file handler allows any client to access the… | |
| Analizada | Media (5.1) | 0.43% | — | The-guild Graphql Mesh | 20/2/2025 | 17/6/2026 | GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on the root level or single source with transforms, and the client… | |
| Analizada | Media (5.3) | 0.37% | — | Meshtastic Firmware | 18/2/2025 | 17/6/2026 | Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with PKC. This issue has been addressed in version 2.5.19 and all users are advised to upgrade. There are no known workarounds… | |
| Aplazada | Crítica (9.3) | 2.4% | 💥 Exploit | Hirsch Enterphone MeshAI | 15/2/2025 | 17/6/2026 | The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps.… |