Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.59% | 💥 PoC | DahuaAI | 10/6/2026 | 23/7/2026 | A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service. | |
| Aplazada | Media (6.9) | 0.54% | 💥 PoC | DahuaAI | 10/6/2026 | 23/7/2026 | A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service. | |
| Aplazada | Baja (2.3) | 0.27% | 💥 PoC | DahuaAI | 10/6/2026 | 23/7/2026 | A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker could issue fraudulent certificates trusted by those clients and undermine the certificate trust chain. | |
| Pendiente de análisis | Baja (2.4) | 0.23% | — | Dahua NVRAIDahua XVRAI | 18/3/2026 | 17/6/2026 | A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges. | |
| Aplazada | Media (6.8) | 0.46% | 💥 PoC | Dahua Embedded ProductsAI | 15/10/2025 | 17/6/2026 | A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. This may cause tampering with… | |
| Aplazada | Crítica (10) | 0.81% | — | Dahua Smart Park Integrated Management PlatformAI | 27/8/2025 | 3/9/2026 | A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via… | |
| Aplazada | Crítica (10) | 15% | 💥 Exploit | Dahua EimsAI | 27/8/2025 | 26/9/2026 | A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is processed without sanitization or… | |
| Analizada | Media (5.5) | 0.63% | — | Dahuatech Monitoring Platform | 9/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Dinstar Monitoring Platform 甘肃省危险品库监控平台 1.0. Affected is an unknown function of the file /itc/$%7BappPath%7D/login_getPasswordErrorNum.action. The manipulation of the argument userBean.loginName leads to sql injection. It is possible to launch the attack… | |
| Aplazada | Alta (8.1) | 0.82% | — | DahuaAI | 23/7/2025 | 17/6/2026 | A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such as Address Space… | |
| Aplazada | Alta (8.1) | 0.86% | 💥 PoC | DahuaAI | 23/7/2025 | 17/6/2026 | A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such as Address Space… | |
| Aplazada | Alta (8.7) | 0.51% | — | Dahua Smart Cloud GatewayAI | 1/7/2025 | 17/6/2026 | An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary SQL statements and potentially… | |
| Aplazada | Media (5.3) | 0.58% | — | Dahua Ipc-hfw1200sAIDahua Ipc-hfw2300r-zAIDahua Ipc-hfw5220e-zAIDahua Ipc-hdw1200sAI | 5/1/2025 | 17/6/2026 | A vulnerability was found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal:… | |
| Modificada | Crítica (9.8) | 0.49% | — | Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+54 | 31/7/2024 | 17/6/2026 | A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization. | |
| Modificada | Alta (7.5) | 0.56% | — | Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+52 | 31/7/2024 | 17/6/2026 | A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash. | |
| Modificada | Alta (7.5) | 0.56% | — | Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+52 | 31/7/2024 | 17/6/2026 | A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash. | |
| Analizada | Media (6.5) | 0.46% | — | Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+52 | 31/7/2024 | 17/6/2026 | A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash. | |
| Analizada | Alta (7.2) | 0.44% | — | Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+52 | 31/7/2024 | 17/6/2026 | A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing device initialization. | |
| Modificada | Media (4.9) | 0.46% | — | Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+52 | 31/7/2024 | 17/6/2026 | A vulnerability has been found in Dahua products. After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash. | |
| Modificada | Alta (7.5) | 0.56% | — | Dahuasecurity Nvr4104-4ks2/l FirmwareDahuasecurity Nvr4108-4ks2/l FirmwareDahuasecurity Nvr4116-4ks2/l FirmwareDahuasecurity Nvr4104-p-4ks2/l Firmware+54 | 31/7/2024 | 17/6/2026 | A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash. | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | Dahuasecurity Smart Parking Management | 22/7/2023 | 17/6/2026 | A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has… | |
| Modificada | Media (4.6) | 0.46% | — | Dahuasecurity Smart Parking Management | 6/6/2023 | 17/6/2026 | A vulnerability has been found in Dahua Smart Parking Management up to 20230528 and classified as problematic. This vulnerability affects unknown code of the file /ipms/imageConvert/image. The manipulation of the argument fileUrl leads to server-side request forgery. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.3) | 0.44% | — | Dahuasecurity Ipc-hf71242f-z-x FirmwareDahuasecurity Ipc-hf7442f-z-x FirmwareDahuasecurity Ipc-hf7842f-z-x FirmwareDahuasecurity Ipc-hf5241f-ze Firmware+93 | 9/2/2023 | 17/6/2026 | Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the vulnerable interface, an attacker can modify the device system time. | |
| Modificada | Media (5.9) | 0.68% | — | Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the… | |
| Modificada | Baja (3.7) | 0.64% | — | Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could get the traceroute results. | |
| Modificada | Media (5.3) | 0.72% | — | Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs from remote DSS Server. |