Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.46% | — | Slack Nebula MeshAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-subscriptions). No admin check exists on this field. At delivery time,… | |
| Aplazada | Alta (8.1) | 0.45% | — | Nebula-meshAISlack NebulaAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's config.yml, a Blocked host retains full overlay reachability to every… | |
| Aplazada | Media (5.4) | 0.32% | — | Nebula-meshAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-network network_config.enrollment_token_ttl overrides. API host creation and… | |
| Aplazada | Media (5.3) | 0.60% | — | Nebula-meshAI | 4/9/2026 | 9/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is registered outside the Web UI rate-limited auth routes. Every request creates a fresh random OIDC state value and stores… | |
| Aplazada | Alta (7.1) | 0.18% | — | Slack Nebula MeshAISlack NebulaAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.LoadByID decrypts the CA's ed25519 private key into a *pki.CAManager, but Build never calls… | |
| Aplazada | Alta (7.1) | 0.35% | — | Nebula-meshAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a cookie and valid for 24 hours. Anyone… | |
| Aplazada | Media (6.9) | 0.31% | — | Slack Nebula MeshAINebula-mesh Nebula-mgmtAI | 4/9/2026 | 8/9/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate issuance time — only… | |
| Aplazada | Alta (8.7) | 0.44% | — | OpennebulaAI | 1/9/2026 | 1/9/2026 | A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper… | |
| Aplazada | Crítica (9.3) | 0.36% | — | Nebula GraphAI | 26/8/2026 | 24/9/2026 | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and writing gflags alongside status and statistics. Neither the service nor… | |
| Aplazada | Alta (8.7) | 0.48% | — | Velodyne Vlp32AISlack NebulaAI | 17/8/2026 | 24/9/2026 | TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. Attackers can send a malformed… | |
| Aplazada | Alta (8.8) | 0.48% | — | Slack Nebula MeshAI | 28/7/2026 | 30/7/2026 | Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not implemented in the web read/mutation surface. Any… | |
| Aplazada | Media (4.6) | 0.32% | — | Nebula-meshAI | 28/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not… | |
| Aplazada | Media (5.5) | 0.15% | — | Nebula-meshAI | 28/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2. | |
| Aplazada | Alta (7.1) | 0.41% | — | Nebula-meshAI | 28/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGetAuditLog does no admin check. The route is bearer-auth gated only; any operator API key returns the full audit log via store.ListAuditEntries (up to limit=1000). This… | |
| Aplazada | Media (6.9) | 0.22% | — | Nebula-meshAI | 28/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DELETE route processes the request as soon as the session cookie validates. SameSite=Lax on the session cookie prevents most cross-site form submits but does not protect:… | |
| Aplazada | Media (6.9) | 0.51% | — | Slack Nebula-meshAI | 28/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the plaintext ed25519.PrivateKey after unwrapping via the master key; internal/pki/ca.go:13-16 stores it. Callers at internal/api/enroll.go:116,… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Nebula-meshAI | 23/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: "API trusts the bearer token for… | |
| Aplazada | Alta (7.1) | 0.53% | — | Nebula-meshAI | 23/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Content-Security-Policy`, `X-Frame-Options`, `Strict-Transport-Security`,… | |
| Aplazada | Alta (8.7) | 0.47% | — | Nebula-meshAI | 23/7/2026 | 30/7/2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a `text/template` that produces the agent's `config.yml`.… | |
| Aplazada | Alta (7.5) | 0.22% | — | MalwarebytesAIMalwarebytes NebulaAI | 9/6/2026 | 23/7/2026 | An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encryption utilities. | |
| Aplazada | Media (6.2) | 0.12% | — | MalwarebytesAIMalwarebytes NebulaAIMozilla FirefoxAI | 9/6/2026 | 23/7/2026 | An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service. | |
| Analizada | Media (6.1) | 0.18% | — | Opennebula | 29/4/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual network template parameter. | |
| Analizada | Media (6.1) | 0.18% | — | Opennebula | 29/4/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter. | |
| Analizada | Media (6.1) | 0.18% | — | Opennebula | 29/4/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute parameter. | |
| Analizada | Media (6.1) | 0.18% | — | Opennebula | 29/4/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. |