Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.79%—Apache Eventmesh14/2/202517/6/2026
CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can use the code under…
AplazadaMedia (4.3)0.26%—Redhat Openshift Service MeshAIEnvoyproxy EnvoyAI28/1/202517/6/2026
The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh logs, leading to log injection and…
ModificadaAlta (7.1)0.41%—Redhat Openshift Service Mesh28/1/202517/6/2026
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.
AplazadaMedia (4.3)0.16%—Mythemeshop Schema LiteAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop Schema Lite allows Cross Site Request Forgery.This issue affects Schema Lite: from n/a through 1.2.2.
AplazadaMedia (4.3)0.26%—SAP HCM Approve TimesheetsAI10/12/202417/6/2026
SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not impacted.
AplazadaBaja (3.5)0.21%—Tp-link Mesh Wi-fi Router Rp562bAI12/11/202417/6/2026
Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain information of the other devices connected through the Wi-Fi.
AplazadaMedia (4.6)0.20%—Mesh Wi-fi Router Rp562bAI12/11/202417/6/2026
Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain or alter the settings of the device .
ModificadaMedia (5.4)0.26%—Brandevolutionco Themeshark Templates & Widgets FOR Elementor9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeshark ThemeShark Templates & Widgets for Elementor themeshark-elementor allows Stored XSS.This issue affects ThemeShark Templates & Widgets for Elementor: from n/a through <= 1.1.7.
AnalizadaAlta (7.5)0.42%—Meshtastic Firmware4/11/202417/6/2026
Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFFFF) which could result in unexpected behavior and potential for DDoS attacks on the network. A malicious actor could craft a packet to be…
AnalizadaAlta (8.5)0.20%—Siemens Intermesh 7177 Hybrid 2.0 SubscriberSiemens Intermesh 7707 Fire Subscriber Firmware23/10/202417/6/2026
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The affected devices contain a SUID binary that could allow an authenticated local…
AnalizadaMedia (6.9)0.37%—Siemens Intermesh 7177 Hybrid 2.0 SubscriberSiemens Intermesh 7707 Fire Subscriber Firmware23/10/202417/6/2026
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices allows to write arbitrary files to the web…
AnalizadaMedia (6.9)0.51%—Siemens Intermesh 7177 Hybrid 2.0 SubscriberSiemens Intermesh 7707 Fire Subscriber Firmware23/10/202417/6/2026
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not authenticate GET requests that execute…
AnalizadaCrítica (10)1.2%—Siemens Intermesh 7177 Hybrid 2.0 SubscriberSiemens Intermesh 7707 Fire Subscriber Firmware23/10/202417/6/2026
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not sanitize the input parameters in…
AplazadaCrítica (9.6)0.61%—Vilo 5 Mesh Wifi SystemAI21/10/20245/7/2026
A Buffer Overflow vulnerability in the local_app_set_router_wifi_SSID_PWD function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via a password field larger than 64 bytes in length.
AplazadaCrítica (9.6)0.61%—Vilo 5 Mesh Wifi SystemAI21/10/20245/7/2026
A Buffer Overflow vulnerability in the local_app_set_router_wan function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via pppoe_username and pppoe_password fields being larger than 128 bytes in length.
AplazadaCrítica (9.6)0.41%—Vilo Mesh Wifi SystemAI21/10/20245/7/2026
A Buffer Overflow vulnerabilty in the local_app_set_router_token function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via sscanf reading the token and timezone JSON fields into a fixed-length buffer.
AnalizadaMedia (6.4)0.19%—Meshtastic Firmware7/10/202417/6/2026
Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic firmware is an open source firmware implementation for the broader project. The remote hardware module of the firmware does not have proper checks to ensure a remote hardware control message…
AnalizadaMedia (5.3)0.44%—Rems Online Timesheet APP29/9/202417/6/2026
A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of the component Add Timesheet Form. The manipulation of the argument day/task leads to cross site scripting. The attack can be…
AnalizadaMedia (5.3)0.53%—Rems Online Timesheet APP29/9/202417/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of the argument timesheet leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaCrítica (9.8)0.46%—Meshtastic Firmware25/9/202417/6/2026
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet connection or proxied through a connected phone (i.e., via bluetooth). Prior to version 2.5.1, multiple…
ModificadaMedia (5.4)0.35%—Livemeshelementor Addons FOR Elementor25/9/202417/6/2026
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_settings’ parameter in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
ModificadaMedia (5.4)0.24%—Livemeshelementor Addons FOR Elementor25/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Cross-Site Scripting (XSS).This issue affects Livemesh Addons for Elementor: from n/a through <= 8.5.
AplazadaCrítica (9.8)0.73%—Btstack MeshAI18/9/202417/6/2026
Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component
AnalizadaAlta (7.5)0.60%—Meshtastic Firmware27/8/202417/6/2026
Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic device firmware is subject to a denial of serivce vulnerability in MQTT handling, fixed in version 2.4.1 of the Meshtastic firmware and…
AplazadaMedia (6.5)0.26%—Livemesh Addons FOR Wpbakery Page BuilderAI18/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for WPBakery Page Builder addons-for-visual-composer allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through 3.9.
Orbitaley — Vulnerabilidades