Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
415 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Arubanetworks ArubaosHP Instantos | 14/5/2024 | 17/6/2026 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Crítica (9.8) | 1.1% | — | Arubanetworks ArubaosHP Instantos | 14/5/2024 | 17/6/2026 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Analizada | Media (5.4) | 0.40% | — | Instantcms | 5/4/2024 | 17/6/2026 | InstantCMS is a free and open source content management system. An open redirect was found in the ICMS2 application version 2.16.2 when being redirected after modifying one's own user profile. An attacker could trick a victim into visiting their web application, thinking they are still present on the ICMS2… | |
| Analizada | Alta (7.2) | 0.85% | — | Instantcms | 4/4/2024 | 17/6/2026 | InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthorized SQL code. The vulnerability exists in index_chart_data action, which receives an input from user… | |
| Modificada | Media (6.5) | 0.79% | — | Connekthq Instant Images - ONE Click Unsplash Uploads | 5/2/2024 | 17/6/2026 | The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the instant-images/license REST API endpoint in… | |
| Modificada | Alta (8.8) | 0.80% | — | Connekthq Instant Images | 22/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions. | |
| Modificada | Media (6.5) | 0.80% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point. | |
| Modificada | Alta (7.2) | 0.94% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles. | |
| Modificada | Alta (7.2) | 1.8% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.5) | 0.87% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the soft ap daemon accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point. | |
| Modificada | Alta (7.5) | 0.87% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Wi-Fi Uplink service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | |
| Modificada | Alta (7.5) | 0.87% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | |
| Modificada | Alta (7.5) | 0.87% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | |
| Modificada | Alta (7.5) | 0.87% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. | |
| Modificada | Alta (8.2) | 0.69% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | There is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal… | |
| Modificada | Alta (8.2) | 0.69% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt… | |
| Modificada | Alta (8.2) | 0.69% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal… | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the… | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosHP Instantos | 14/11/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Alta (8.8) | 0.27% | — | Dylanblokhuis Instant CSS | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dylan Blokhuis Instant CSS plugin <= 1.2.1 versions. | |
| Modificada | Alta (7.2) | 0.90% | — | Instantcms Icms2 | 13/9/2023 | 17/6/2026 | SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1. | |
| Modificada | Media (4.8) | 0.40% | — | Instantcms | 10/9/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git. | |
| Modificada | Media (5.4) | 0.38% | — | Instantcms | 10/9/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |
| Modificada | Media (4.9) | 0.89% | — | Instantcms | 1/9/2023 | 17/6/2026 | External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |