Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.3)0.09%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead of the address configured on the…
RechazadaSin puntuar——Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
AplazadaAlta (7.9)0.28%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/20261/10/2026
Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856. Improper Control…
AplazadaMedia (4.4)0.10%—Mesalvo Meona Client LauncherAIMesalvo Meona ServerAI20/5/202625/9/2026
Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected stored passwords with SHA-1 (versions from October 2015) or stored them without…
AplazadaAlta (7.8)0.13%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verify the role asserted by the MEONA Client. A user who holds a valid MEONA user…
AnalizadaCrítica (9.6)1.1%⚠ Explotación activaTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
ModificadaCrítica (9.8)0.61%—Mesa3d Mesa12/4/202613/7/2026
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
AnalizadaCrítica (9.8)0.54%—Mesa Project Mesa6/3/202617/6/2026
Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been patched via commit c35b8cd.
AplazadaMedia (4.3)0.18%—Themesawesome History TimelineAI31/12/202523/9/2026
Missing Authorization vulnerability in themesawesome History Timeline timeline-awesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects History Timeline: from n/a through <= 1.0.6.
AplazadaMedia (5.9)0.22%—Mesa Mesa Reservation WidgetAI28/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gslauraspeck Mesa Mesa Reservation Widget mesa-mesa-reservation-widget allows Stored XSS.This issue affects Mesa Mesa Reservation Widget: from n/a through <= 1.0.0.
AplazadaMedia (6.9)0.30%—Nimesa Backup AND RecoveryAI7/7/202517/6/2026
Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulnerability is exploited, unintended requests may be sent to internal servers.
AplazadaCrítica (9.3)1.3%—Nimesa Backup AND RecoveryAI7/7/202517/6/2026
An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running.
AnalizadaMedia (4.3)0.17%—Themesawesome Sakolawp27/2/202517/6/2026
The School Management System – SakolaWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the 'save_exam_setting' and 'delete_exam_setting' actions. This makes it possible for unauthenticated attackers…
AplazadaCrítica (9.8)0.64%—Themesawesome SakolawpAI7/1/202517/6/2026
The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an…
AplazadaMedia (6.9)0.39%—Vimesa Vhf/fm Transmitter Blue PlusAI24/10/202417/6/2026
VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attacker can issue an unauthorized HTTP GET request to the unprotected endpoint 'doreboot' and restart the transmitter operations.
ModificadaMedia (4.3)0.54%—Mesa3d Mesa27/3/202417/6/2026
glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
ModificadaMedia (5.3)0.39%—Mesa3d Mesa27/3/202417/6/2026
Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
ModificadaAlta (7.5)1.0%—Mesa3d Mesa27/3/202417/6/2026
Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.
ModificadaMedia (6.2)0.28%—Mesa3d Mesa27/3/202417/6/2026
Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in…
ModificadaMedia (5.4)0.56%—Themesawesome Timeline Awesome23/9/202217/6/2026
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin <= 1.0.5 at WordPress.
ModificadaCrítica (9.8)0.98%—Mesalabs Amegaview21/12/202117/6/2026
Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application, which may allow an attacker to gain access.
ModificadaCrítica (9.8)0.80%—Mesalabs Amegaview21/12/202117/6/2026
Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to the device.
ModificadaAlta (8.8)3.1%—Mesalabs Amegaview21/12/202117/6/2026
Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute commands in the web server.
ModificadaCrítica (9.8)2.3%—Mesalabs Amegaview21/12/202117/6/2026
Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.8)0.22%—Mesalabs Amegaview21/12/202117/6/2026
Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges on the device.