Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 0.48% | — | Pebblepower Pebble Prism Ultra Firmware | 4/3/2026 | 17/6/2026 | A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over… | |
| Analizada | Media (4.8) | 0.85% | — | Pebbletemplates Pebble Templates | 27/2/2025 | 17/6/2026 | Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker can access sensitive local files by crafting malicious notification templates that leverage this tag to include files like /etc/passwd or… | |
| Analizada | Media (6.5) | 0.20% | — | Canonical Pebble | 4/4/2024 | 17/6/2026 | It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4. | |
| Modificada | Crítica (9.8) | 1.5% | — | Pebbletemplates Pebble Templates | 12/9/2022 | 17/6/2026 | Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, and thus either the input should not arrive from an untrusted source,… | |
| Modificada | Media (5.9) | 1.3% | — | Creative Pebble V3 FirmwareCreative Pebble V2 FirmwareCreative Pebble FirmwareCreative Pebble Plus Firmware | 11/8/2021 | 17/6/2026 | CREATIVE Pebble devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power… | |
| Modificada | Crítica (9.8) | 1.3% | — | Pebbletemplates Pebble Templates | 19/12/2019 | 17/6/2026 | Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature. | |
| Modificada | Media (6.1) | 0.65% | — | Pebble Firmware | 28/11/2017 | 17/6/2026 | Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's flash storage, and access an arbitrary application's JavaScript instance, by modifying a UUID value within the header of a crafted application binary. | |
| Modificada | Media (4.3) | 1.2% | — | Simon Brown Pebble | 8/11/2012 | 16/6/2026 | CRLF injection vulnerability in Pebble before 2.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | |
| Modificada | Media (6.4) | 1.5% | — | Simon Brown Pebble | 8/11/2012 | 16/6/2026 | Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment. | |
| Modificada | Media (5.8) | 1.3% | — | Simon Brown Pebble | 4/11/2012 | 16/6/2026 | Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Simon Brown Pebble | 25/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Pebble before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Simon Brown Pebble | 10/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to inject arbitrary web script or HTML via the query string. |