Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.2) | 0.18% | — | Instar 2K+AIInstar 4KAI | 13/8/2025 | 17/6/2026 | A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the component UART Interface. The manipulation leads to improper physical access control. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be… | |
| Aplazada | Alta (7.7) | 8.0% | — | Instar 2K+AIInstar 4KAI | 13/8/2025 | 17/6/2026 | A vulnerability has been found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This vulnerability affects unknown code of the component Backend IPC Server. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Crítica (9.3) | 0.78% | — | Instar 2K PlusAIInstar 4KAI | 13/8/2025 | 17/6/2026 | A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely. | |
| Aplazada | Media (6.5) | 0.24% | — | Winstar Wn572hp3AI | 2/7/2025 | 5/7/2026 | WINSTAR WN572HP3 v230525 was discovered to contain a heap overflow via the CONTENT_LENGTH variable at /cgi-bin/upload.cgi. | |
| Aplazada | Media (6.4) | 0.50% | — | InstarisacsAI | 13/8/2024 | 17/6/2026 | This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo parameter in user login module of the web interface of the application. A remote attacker could exploit this vulnerability by sending a specially crafted input to the vulnerable parameter to perform… | |
| Modificada | Media (6.1) | 0.60% | — | Instareza Mail Control | 12/7/2023 | 17/6/2026 | The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 0.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (5.4) | 0.50% | — | Dinstar Dag2000-16o Firmware | 28/11/2022 | 17/6/2026 | Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Alta (7.5) | 0.92% | — | Coinstar Myadvancedtoken Project Coinstar Myadvancedtoken | 3/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Coinstar (CSTR), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (5.4) | 0.27% | — | Instaroid - Instagram Viewer Project Instaroid - Instagram Viewer | 30/9/2014 | 17/6/2026 | The Instaroid - Instagram Viewer (aka net.muik.instaroid) application 1.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |