Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.6)0.48%—Pebblepower Pebble Prism Ultra Firmware4/3/202617/6/2026
A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over…
AnalizadaMedia (4.8)0.85%—Pebbletemplates Pebble Templates27/2/202517/6/2026
Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker can access sensitive local files by crafting malicious notification templates that leverage this tag to include files like /etc/passwd or…
AnalizadaMedia (6.5)0.20%—Canonical Pebble4/4/202417/6/2026
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4.
ModificadaCrítica (9.8)1.5%—Pebbletemplates Pebble Templates12/9/202217/6/2026
Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, and thus either the input should not arrive from an untrusted source,…
ModificadaMedia (5.9)1.3%—Creative Pebble V3 FirmwareCreative Pebble V2 FirmwareCreative Pebble FirmwareCreative Pebble Plus Firmware11/8/202117/6/2026
CREATIVE Pebble devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power…
ModificadaCrítica (9.8)1.3%—Pebbletemplates Pebble Templates19/12/201917/6/2026
Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature.
ModificadaMedia (6.1)0.65%—Pebble Firmware28/11/201717/6/2026
Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's flash storage, and access an arbitrary application's JavaScript instance, by modifying a UUID value within the header of a crafted application binary.
ModificadaMedia (4.3)1.2%—Simon Brown Pebble8/11/201216/6/2026
CRLF injection vulnerability in Pebble before 2.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
ModificadaMedia (6.4)1.5%—Simon Brown Pebble8/11/201216/6/2026
Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment.
ModificadaMedia (5.8)1.3%—Simon Brown Pebble4/11/201216/6/2026
Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (4.3)1.0%—Simon Brown Pebble25/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in Pebble before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.2%—Simon Brown Pebble10/10/200616/6/2026
Cross-site scripting (XSS) vulnerability in the search functionality in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to inject arbitrary web script or HTML via the query string.