Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.33% | — | Livemeshelementor Addons FOR Elementor | 14/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Elementor Addons by Livemesh allows Stored XSS.This issue affects Elementor Addons by Livemesh: from n/a through 8.3.5. | |
| Modificada | Media (5.4) | 0.32% | — | Livemeshthemes Wpbakery Page Builder Addons | 13/3/2024 | 17/6/2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'per_line_mobile' shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.43% | — | Livemeshelementor Addons FOR Elementor | 29/2/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom class field in all versions up to, and including, 8.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to… | |
| Analizada | Alta (8.8) | 0.46% | — | Meshcentral | 20/2/2024 | 17/6/2026 | MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is the primary mechanism used within MeshCentral to perform administrative actions on the server. The vulnerability is exploitable when an… | |
| Modificada | Media (5.4) | 0.51% | — | Livemesh Elementor Addons | 5/2/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget URL parameters in all versions up to, and including, 8.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or… | |
| Modificada | Alta (7.5) | 0.53% | — | Meshcentral | 2/2/2024 | 17/6/2026 | Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm. | |
| Modificada | Crítica (9.8) | 0.47% | — | Meshcentral | 30/1/2024 | 17/6/2026 | Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation. | |
| Modificada | Alta (7.5) | 0.83% | — | Meshcentral | 29/1/2024 | 17/6/2026 | An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16. | |
| Modificada | Alta (8.8) | 0.52% | — | Mythemeshop URL Shortener | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17. | |
| Modificada | Media (5.4) | 0.38% | — | Livemeshthemes Wpbakery Page Builder Addons | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh WPBakery Page Builder Addons by Livemesh allows Stored XSS.This issue affects WPBakery Page Builder Addons by Livemesh: from n/a through 3.5. | |
| Modificada | Crítica (9.8) | 1.3% | — | Layer5 Meshery | 24/11/2023 | 17/6/2026 | A SQL injection vulnerability exists in Meshery prior to version v0.6.179, enabling a remote attacker to retrieve sensitive information and execute arbitrary code through the “order” parameter | |
| Modificada | Alta (8.8) | 0.31% | — | Mythemeshop WP Shortcode | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (6.1) | 0.38% | — | Mythemeshop URL Shortener | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 versions. | |
| Modificada | Media (4.3) | 0.74% | — | KialiRedhat Openshift Service Mesh | 23/9/2023 | 17/6/2026 | A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed. | |
| Modificada | Media (6.1) | 0.37% | — | Dharmeshpatel Post List With Featured Image | 1/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dharmesh Patel Post List With Featured Image plugin <= 1.2 versions. | |
| Analizada | Crítica (9.8) | 1.3% | — | Apache Eventmesh-connector-rabbitmq | 17/7/2023 | 17/6/2026 | CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. Users can use the code under the master branch in project… | |
| Modificada | Media (6.1) | 0.63% | — | Students Online Internship Timesheet System Project Students Online Internship Timesheet System | 30/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Students Online Internship Timesheet Syste 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_company. The manipulation of the argument name with the input… | |
| Modificada | Crítica (9.8) | 0.78% | — | Students Online Internship Timesheet System Project Students Online Internship Timesheet System | 29/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet System 1.0. Affected is an unknown function of the file rendered_report.php of the component GET Parameter Handler. The manipulation of the argument sid leads to sql injection. It is possible to launch… | |
| Modificada | Media (5.4) | 0.44% | — | Timesheets-for-jira Timesheet Tracking | 17/4/2023 | 17/6/2026 | The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view. | |
| Modificada | Alta (8.8) | 1.1% | — | Admesh Project AdmeshLibslic3r | 3/4/2023 | 17/6/2026 | An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Media (5.5) | 0.33% | — | Vox2mesh Project Vox2mesh | 22/3/2023 | 17/6/2026 | vox2mesh 1.0 has stack-overflow in main.cpp, this is stack-overflow caused by incorrect use of memcpy() funciton. The flow allows an attacker to cause a denial of service (abort) via a crafted file. | |
| Modificada | Media (5.5) | 0.17% | — | Steptools Ifcmesh Library | 13/3/2023 | 17/6/2026 | STEPTools v18SP1 ifcmesh library (v18.1) is affected due to a null pointer dereference, which could allow an attacker to deny application usage when reading a specially constructed file, resulting in an application crash. | |
| Modificada | Alta (8.8) | 0.78% | — | Infineon Cypress Bluetooth Mesh Software Development KIT | 1/2/2023 | 17/6/2026 | Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is lower_transport_layer_on_seg. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write… | |
| Modificada | Alta (8.8) | 0.78% | — | Infineon Cypress Bluetooth Mesh Software Development KIT | 1/2/2023 | 17/6/2026 | Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability… |