Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 304 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.3) | 0.09% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead of the address configured on the… | |
| Rechazada | Sin puntuar | — | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| Aplazada | Alta (7.9) | 0.28% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 1/10/2026 | Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856. Improper Control… | |
| Aplazada | Media (4.4) | 0.10% | — | Mesalvo Meona Client LauncherAIMesalvo Meona ServerAI | 20/5/2026 | 25/9/2026 | Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected stored passwords with SHA-1 (versions from October 2015) or stored them without… | |
| Aplazada | Alta (7.8) | 0.13% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verify the role asserted by the MEONA Client. A user who holds a valid MEONA user… | |
| Analizada | Alta (7.5) | 0.55% | — | Salvo | 24/3/2026 | 17/6/2026 | Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated external attacker to bypass proxy routing constraints and access unintended backend paths (e.g., protected endpoints or… | |
| Analizada | Alta (8.7) | 0.52% | — | Salvo | 24/3/2026 | 17/6/2026 | Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading request bodies into memory. This allows attackers to cause Out-of-Memory (OOM) conditions by sending extremely large… | |
| Analizada | Alta (8.8) | 0.34% | — | Salvo | 8/1/2026 | 17/6/2026 | Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may potentially lead to XSS in cases where a website allow the access to public files using this feature and anyone can upload a file. This issue… | |
| Analizada | Alta (8.8) | 0.34% | — | Salvo | 8/1/2026 | 17/6/2026 | Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder which include a render of the current path, in which its inserted in the HTML without proper sanitation, this leads to reflected XSS using the fact that request path is decoded and normalized in the… | |
| Modificada | Media (5) | 8.6% | — | Salvo G. Tomaselli Weborf | 24/9/2010 | 16/6/2026 | Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI. | |
| Modificada | Media (5) | 6.5% | — | Salvo Tomaselli Weborf Http Server | 24/6/2010 | 16/6/2026 | Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header, and possibly other headers. |