VulnSea

Mesalvo has 4 CVEs on record. The busiest recent month was May 2026 with 4. The median CVSS is 6.1 (medium). Most affected products: Meona Client (2), Meona Client Launcher Component (1), Meona Server (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
—
Last 90 days
0 prev 4

Products

  • Meona Client 2
  • Meona Client Launcher Component 1
  • Meona Server 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Mesalvo vulnerabilities

CVEs affecting Mesalvo, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-0856High· 7.8
4mo ago

Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel)

Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verif…

▾ TwilightMesalvo · Meona ClientEPSS 0.13%via NVD
CVE-2026-0857Medium· 4.4
4mo ago

Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10

Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected st…

▾ SunlitMesalvo · Meona ClientEPSS 0.10%via NVD
CVE-2026-25602Low· 2.3
4mo ago

Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server)

Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the…

▾ SunlitMesalvo · Meona ServerEPSS 0.10%via NVD
CVE-2026-22314High· 7.9
4mo ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher C…

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher C…

▾ TwilightMesalvo · Meona Client Launcher ComponentEPSS 0.39%via NVD
Mesalvo vulnerabilities (CVEs) · VulnSea