Instedd is a small, focused vendor centered on communication and information-sharing platforms for humanitarian and public-health applications, with identified vulnerabilities clustering in products such as Nuntium and Pollit. The observed weakness classes center on information-disclosure and timing-related issues, reflecting the data-handling and authentication demands of systems designed for crisis communication and disease surveillance.
The number and severity of CVEs published that impact products developed by Instedd over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-20179CRITICAL A vulnerability was found in InSTEDD Pollit 2.3.1. It has been rated as critical. This issue affects the function TourController of the file app/controllers/tour_controller.rb. The | Feb 21, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-4823MEDIUM A vulnerability, which was classified as problematic, was found in InSTEDD Nuntium. Affected is an unknown function of the file app/controllers/geopoll_controller.rb. The manipulat | Dec 28, 2022 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Instedd.
Media articles that mention a CVE ID that affects a product developed by Instedd — matched by CVE ID, not by vendor name.