Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.3)0.09%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead of the address configured on the…
RechazadaSin puntuar——Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
AplazadaAlta (7.9)0.28%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/20261/10/2026
Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856. Improper Control…
AplazadaMedia (4.4)0.10%—Mesalvo Meona Client LauncherAIMesalvo Meona ServerAI20/5/202625/9/2026
Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected stored passwords with SHA-1 (versions from October 2015) or stored them without…
AplazadaAlta (7.8)0.13%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verify the role asserted by the MEONA Client. A user who holds a valid MEONA user…
AplazadaAlta (8.1)0.52%—Mikado-themes EonaAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Eona eona allows PHP Local File Inclusion.This issue affects Eona: from n/a through <= 1.3.
AplazadaMedia (6.4)0.29%—WP GeonamesAI12/12/202417/6/2026
The WP GeoNames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-geonames' shortcode in all versions up to, and including, 1.9.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.29%—Jacques Malgrange WP GeonamesAI6/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacques Malgrange WP GeoNames wp-geonames allows Reflected XSS.This issue affects WP GeoNames: from n/a through <= 1.8.
ModificadaMedia (6.3)0.32%—David Leonard Pkstat5/5/201416/6/2026
tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.
ModificadaAlta (7.5)3.6%—Seth Leonard Book OF GuestsSeth Leonard Post IT6/12/200116/6/2026
Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.
Orbitaley — Vulnerabilidades