Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.74%—Bestechnic Bluetooth Mesh Software Development KIT1/2/202317/6/2026
In Bestechnic Bluetooth Mesh SDK (BES2300) V1.0, a buffer overflow vulnerability can be triggered during provisioning, because there is no check for the SegN field of the Transaction Start PDU.
ModificadaAlta (7.5)11%—Netcommwireless Nf20 FirmwareNetcommwireless Nf20mesh FirmwareNetcommwireless Nl1902 Firmware11/1/202317/6/2026
Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the…
ModificadaCrítica (9.8)7.2%—Netcommwireless Nf20 FirmwareNetcommwireless Nf20mesh FirmwareNetcommwireless Nl1902 Firmware11/1/202317/6/2026
On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location.
ModificadaMedia (6.5)0.32%—Dolibarr Project Timesheet Project Dolibarr Project Timesheet27/12/202217/6/2026
A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading to version 4.5.6.a is able to address…
ModificadaAlta (8.8)35%—Intelbras Wifiber 120ac Inmesh Firmware25/12/202217/6/2026
Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.
ModificadaMedia (4.8)0.47%—Livemeshelementor Addons FOR Elementor12/12/202217/6/2026
The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (4.8)0.60%—Mythemeshop Launcher6/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.
ModificadaMedia (6.5)0.47%—Realtek Bluetooth Mesh Software Development KIT30/8/202217/6/2026
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.
ModificadaMedia (6.5)0.47%—Realtek Bluetooth Mesh Software Development KIT30/8/202217/6/2026
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shift parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.
ModificadaMedia (6.5)0.47%—Realtek Bluetooth Mesh Software Development KIT30/8/202217/6/2026
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ reference parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.
ModificadaMedia (6.5)0.37%—Realtek Bluetooth Mesh Software Development KIT30/8/202217/6/2026
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An unauthenticated attacker in the adjacent network can exploit this vulnerability to disrupt service.
ModificadaCrítica (9.8)1.0%—Redhat Openshift Service MeshRedhat Servicemesh-operator22/8/202217/6/2026
A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…
ModificadaAlta (8.8)0.91%—Nordicsemi Nrf5 SDK FOR Mesh15/8/202217/6/2026
In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented packets with SegO > SegN
ModificadaAlta (8.8)0.91%—Nordicsemi Nrf5 SDK FOR Mesh15/8/202217/6/2026
In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control packets and access packets with the same SeqAuth
ModificadaAlta (7.5)1.0%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A denial of service vulnerability exists in the confctl_set_guest_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.
ModificadaAlta (7.5)0.91%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.
ModificadaAlta (7.5)0.91%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
An information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.
ModificadaAlta (7.5)1.0%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A denial of service vulnerability exists in the confctl_set_master_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.
ModificadaCrítica (9.8)1.2%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A denial of service vulnerability exists in the confctl_set_wan_cfg functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.
ModificadaCrítica (9.8)1.2%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A denial of service vulnerability exists in the ucloud_del_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.
ModificadaCrítica (9.8)1.2%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A buffer overflow vulnerability exists in the confsrv ucloud_set_node_location functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.3%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A stack-based buffer overflow vulnerability exists in the confsrv ucloud_set_node_location functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.2%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A stack-based buffer overflow vulnerability exists in the confsrv addTimeGroup functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.3%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer…
ModificadaCrítica (9.8)1.3%—TCL Linkhub Mesh Wifi Ac12005/8/202217/6/2026
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer…
Orbitaley — Vulnerabilidades