Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.99% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request. | |
| Modificada | Media (6.3) | 0.44% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or… | |
| Modificada | Alta (8.8) | 0.76% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device. | |
| Modificada | Alta (8.8) | 0.89% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely. | |
| Modificada | Alta (7.3) | 0.49% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component | |
| Modificada | Media (6.3) | 0.44% | — | Vivotek Fd8136 Firmware | 2/6/2026 | 22/7/2026 | A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length… | |
| Aplazada | Media (4.3) | 0.36% | — | Rate Star Review VoteAI | 12/5/2026 | 17/6/2026 | The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler lacks both capability checks and nonce verification. The only access control is an is_user_logged_in() check. When the… | |
| Aplazada | Crítica (9.3) | 20% | — | VivotekAI | 13/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR,… | |
| Analizada | Alta (8.6) | 1.5% | — | Vivotek Ip7137 Firmware | 9/1/2026 | 17/6/2026 | Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by… | |
| Analizada | Media (6.9) | 0.83% | — | Vivotek Ip7137 Firmware | 9/1/2026 | 17/6/2026 | Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the… | |
| Analizada | Crítica (9.3) | 0.39% | — | Vivotek Ip7137 Firmware | 9/1/2026 | 17/6/2026 | Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since… | |
| Analizada | Alta (8.7) | 0.41% | — | Vivotek Ip7137 Firmware | 9/1/2026 | 17/6/2026 | Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising… | |
| Modificada | Alta (7.5) | 0.51% | 💥 PoC | Revotech I6032w-fhw Firmware | 2/1/2026 | 5/7/2026 | An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attackers to access sensitive information and escalate privileges via a crafted HTTP request. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Vivotek Device FirmwareAI | 19/11/2025 | 17/6/2026 | Legacy Vivotek Device firmware uses default credetials for the root and user login accounts. | |
| Aplazada | Media (5.1) | 0.37% | — | Vivotek NVR Nd8422pAIVivotek NVR Nd9525pAIVivotek NVR Nd9541pAI | 8/4/2025 | 17/6/2026 | A vulnerability was found in Vivotek NVR ND8422P, NVR ND9525P and NVR ND9541P 2.4.0.204/3.3.0.104/4.2.0.101. It has been classified as problematic. Affected is an unknown function of the component HTML Form Handler. The manipulation leads to inclusion of sensitive information in source code. It is possible to launch… | |
| Aplazada | Media (6.4) | 0.35% | — | Videowhisper Rate Star Review VoteAI | 18/1/2025 | 17/6/2026 | The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Media (6.5) | 0.32% | — | Lequanghuylc Multiple Votes IN ONE PageAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lequanghuylc Multiple Votes in one page multiple-votes-in-one-page allows Stored XSS.This issue affects Multiple Votes in one page: from n/a through <= 1.0.4. | |
| Analizada | Media (5.3) | 2.7% | — | Vivotek Ib8367a Firmware | 3/8/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. It is possible to launch the attack remotely. The identifier of… | |
| Analizada | Media (5.3) | 2.7% | — | Vivotek Sd9364 Firmware | 3/8/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. The attack may be initiated remotely. The associated… | |
| Modificada | Alta (8.7) | 8.1% | — | Vivotek Sd9364 Firmware | 3/8/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack can be initiated remotely. The… | |
| Modificada | Media (5.3) | 2.7% | — | Vivotek Cc8160 Firmware | 3/8/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Alta (8.7) | 1.0% | — | Vivotek Cc8160 Firmware | 3/8/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack may be launched remotely. The exploit… | |
| Analizada | Crítica (9.8) | 1.1% | — | Vivotek Camera Firmware | 29/2/2024 | 17/6/2026 | An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component. | |
| Modificada | Media (6.1) | 0.38% | — | Advcomsys Onevote! | 11/7/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements. | |
| Modificada | Crítica (9.8) | 0.67% | — | Voteapp Project Voteapp | 10/1/2023 | 17/6/2026 | A vulnerability was found in mapoor voteapp. It has been rated as critical. Affected by this issue is the function create_poll/do_poll/show_poll/show_refresh of the file app.py. The manipulation leads to sql injection. The patch is identified as b290c21a0d8bcdbd55db860afd3cadec97388e72. It is recommended to apply a… |