Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.46% | — | Slack Nebula MeshAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-subscriptions). No admin check exists on this field. At delivery time,… | |
| Aplazada | Alta (8.1) | 0.45% | — | Nebula-meshAISlack NebulaAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's config.yml, a Blocked host retains full overlay reachability to every… | |
| Aplazada | Media (5.4) | 0.32% | — | Nebula-meshAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-network network_config.enrollment_token_ttl overrides. API host creation and… | |
| Aplazada | Media (5.3) | 0.60% | — | Nebula-meshAI | 4/9/2026 | 9/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is registered outside the Web UI rate-limited auth routes. Every request creates a fresh random OIDC state value and stores… | |
| Aplazada | Alta (7.1) | 0.18% | — | Slack Nebula MeshAISlack NebulaAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.LoadByID decrypts the CA's ed25519 private key into a *pki.CAManager, but Build never calls… | |
| Aplazada | Alta (7.1) | 0.35% | — | Nebula-meshAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a cookie and valid for 24 hours. Anyone… | |
| Aplazada | Media (6.9) | 0.31% | — | Slack Nebula MeshAINebula-mesh Nebula-mgmtAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate issuance time — only… | |
| Pendiente de análisis | Alta (8.9) | 0.39% | — | Bluetooth Mesh SDKAI | 28/8/2026 | 8/9/2026 | In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted. | |
| Aplazada | Media (6.3) | 0.33% | — | Meshtastic MallaAI | 21/8/2026 | 9/9/2026 | Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered into the DOM without escaping. Any participant on a public Meshtastic MQTT broker can… | |
| Pendiente de análisis | Alta (7) | 0.56% | — | Kong MeshAIKuma KDSAI | 17/8/2026 | 31/8/2026 | On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute… | |
| Pendiente de análisis | Media (6) | 0.43% | — | Kong MeshAI | 12/8/2026 | 31/8/2026 | In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound… | |
| Pendiente de análisis | Media (5.1) | 0.30% | — | Kong MeshAI | 12/8/2026 | 31/8/2026 | The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material. | |
| Pendiente de análisis | Alta (8.6) | 0.22% | — | MeshcentralAI | 30/7/2026 | 9/9/2026 | MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed… | |
| Aplazada | Alta (8.8) | 0.48% | — | Slack Nebula MeshAI | 28/7/2026 | 30/7/2026 | Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not implemented in the web read/mutation surface. Any… | |
| Aplazada | Media (4.6) | 0.32% | — | Nebula-meshAI | 28/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not… | |
| Aplazada | Media (5.5) | 0.15% | — | Nebula-meshAI | 28/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2. | |
| Aplazada | Alta (7.1) | 0.41% | — | Nebula-meshAI | 28/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGetAuditLog does no admin check. The route is bearer-auth gated only; any operator API key returns the full audit log via store.ListAuditEntries (up to limit=1000). This… | |
| Aplazada | Media (6.9) | 0.22% | — | Nebula-meshAI | 28/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DELETE route processes the request as soon as the session cookie validates. SameSite=Lax on the session cookie prevents most cross-site form submits but does not protect:… | |
| Aplazada | Media (6.9) | 0.51% | — | Slack Nebula-meshAI | 28/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the plaintext ed25519.PrivateKey after unwrapping via the master key; internal/pki/ca.go:13-16 stores it. Callers at internal/api/enroll.go:116,… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Nebula-meshAI | 23/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: "API trusts the bearer token for… | |
| Aplazada | Alta (7.1) | 0.53% | — | Nebula-meshAI | 23/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Content-Security-Policy`, `X-Frame-Options`, `Strict-Transport-Security`,… | |
| Aplazada | Alta (8.7) | 0.47% | — | Nebula-meshAI | 23/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a `text/template` that produces the agent's `config.yml`.… | |
| Aplazada | Alta (8.7) | 2.1% | — | Layer5 MesheryAI | 23/7/2026 | 14/9/2026 | Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or traversal sequences in the file parameter to… | |
| Aplazada | Media (6.4) | 0.32% | — | Mythemeshop WP ShortcodeAI | 23/7/2026 | 23/7/2026 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is due to insufficient input sanitization and output escaping in the mts_tabs() function, which outputs the title shortcode… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Turkmesh Communication Services INC Turkhotspot 5651 LoglamaAI | 21/7/2026 | 21/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3. |