Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

415 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)2.9%💥 ExploitInstantcms1/8/202516/6/2026
A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input passed via the look parameter is concatenated into a PHP expression and executed without proper sanitation. A remote attacker can exploit…
AnalizadaBaja (1.9)0.32%—Instantbits WEB Video Cast20/7/202517/6/2026
A vulnerability was found in InstantBits Web Video Cast App up to 5.12.4 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.instantbits.cast.webvideo. The manipulation leads to improper export of android application…
AplazadaCrítica (9.8)1.1%—HPE Networking Instant ON Access PointsAI8/7/202517/6/2026
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.
AplazadaAlta (7.2)1.5%—HPE Networking Instant ON Access PointsAI8/7/202517/6/2026
An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user.
AplazadaAlta (8.6)0.19%—Upkeeper Solutions Upkeeper Instant Privilege AccessAI10/6/202517/6/2026
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abuse.This issue affects upKeeper Instant Privilege Access: before 1.4.0.
AplazadaAlta (8.6)0.21%—Upkeeper Solutions Upkeeper Instant Privilege AccessAI10/6/202517/6/2026
Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects upKeeper Instant Privilege Access: before 1.4.0.
AplazadaCrítica (9.3)0.82%—Instantel MicromateAI30/5/202517/6/2026
Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if connected.
ModificadaAlta (7.2)0.46%💥 PoCThemefic Instantio7/5/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell to a Web Server.This issue affects Instantio: from n/a through <= 3.3.16.
AplazadaMedia (6.5)0.38%—Themefic InstantioAI17/4/202517/6/2026
Missing Authorization vulnerability in Themefic Instantio instantio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Instantio: from n/a through <= 3.3.7.
AplazadaMedia (6)0.25%—Arista Aos-8 InstantAIArista Aos-10 APAI8/4/202517/6/2026
A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating…
AplazadaMedia (6.5)0.45%—Aruba Aos-8 InstantAIAruba Aos-10 APAI8/4/202517/6/2026
A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.
AplazadaAlta (7.1)0.37%—Tenteeglobal Instant AppointmentAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tenteeglobal Instant Appointment instant-appointment allows Reflected XSS.This issue affects Instant Appointment: from n/a through <= 1.2.
AplazadaCrítica (9.3)0.54%—Tenteeglobal Instant AppointmentAI16/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tenteeglobal Instant Appointment instant-appointment allows SQL Injection.This issue affects Instant Appointment: from n/a through <= 1.2.
AplazadaMedia (5.4)0.54%—Dylanblokhuis Instant CSSAI13/12/202417/6/2026
Missing Authorization vulnerability in Dylan Blokhuis Instant CSS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Instant CSS: from n/a through 1.1.4.
AplazadaCrítica (10)0.40%—Upkeeper Solutions Upkeeper Instant Privilege AccessAI20/11/202417/6/2026
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.
AplazadaCrítica (10)0.40%—Upkeeper Solutions Upkeeper Instant Privilege AccessAI20/11/202417/6/2026
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.
AplazadaCrítica (10)0.51%—Bdthemes Instant Image GeneratorAI14/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in bdthemes Instant Image Generator ai-image allows Upload a Web Shell to a Web Server.This issue affects Instant Image Generator: from n/a through <= 1.5.2.
AplazadaMedia (6.8)0.87%—Instant Aos-8AIInstant Aos-10AI5/11/202417/6/2026
An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to a remote unauthorized access to…
AplazadaAlta (7.2)1.2%—Instant Aos-8AIInstant Aos-10AI5/11/202417/6/2026
An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.
AplazadaAlta (7.2)1.2%—Instant Aos-8AIInstant Aos-10AI5/11/202417/6/2026
An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.
AplazadaAlta (7.2)1.7%—Instant Aos-8AIInstant Aos-10AI5/11/202417/6/2026
An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the…
AnalizadaMedia (5.4)0.33%—Instantcms29/10/202417/6/2026
InstantCMS is a free and open source content management system. In photo upload function in the photo album page there is no input validation taking place. Due to this attackers are able to inject the XSS (Cross Site Scripting) payload and execute. This vulnerability is fixed in 2.16.3.
AplazadaAlta (7.5)0.56%—Istmoplugins Instant-chat-floating-button-for-wordpress-websitesAI5/10/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPress Websites instant-chat-wp allows PHP Local File Inclusion.This issue affects Instant Chat Floating Button for WordPress Websites: from n/a through <= 1.0.5.
AplazadaMedia (6.6)0.11%—Entrust Instant Financial IssuanceAI23/9/202417/6/2026
Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process that relies on static hard-coded key values. These keys are not uniquely generated per installation of the software.…
AplazadaMedia (5.9)0.20%—Entrust Instant Financial IssuanceAI23/9/202417/6/2026
Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. WebAPI.cfg.xml) after the installation process. This file can be accessed without authentication on HTTP port 80 by guessing the correct…
Orbitaley — Vulnerabilidades