Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)0.23%—Pysoft Active Webcam16/1/202617/6/2026
Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path by placing malicious executables in specific directory locations to gain administrative access.
AplazadaMedia (6.4)0.19%—Wordpress Live Webcam Widget ShortcodeAI11/10/202517/6/2026
The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (4.6)0.18%—Canon EOS Webcam Utility PROAI26/6/202517/6/2026
Canon EOS Webcam Utility Pro for MAC OS version 2.3d (2.3.29) and earlier contains an improper directory permissions vulnerability. Exploitation of this vulnerability requires administrator access by a malicious user. An attacker could modify the directory, potentially resulting in code execution and ultimately…
AplazadaMedia (6.1)0.18%—WebcamconsultAI18/1/202517/6/2026
The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged…
AplazadaMedia (4.4)0.23%—Logitech Mevo Webcam APPAI23/4/202417/6/2026
Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code.
ModificadaAlta (7.5)1.3%—Webcamserver Project Webcamserver10/5/202317/6/2026
Buffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 allows a remote attacker to cause a denial of service via the WebcamServer.exe file.
ModificadaMedia (5.4)0.47%—React Webcam Project React Webcam20/3/202317/6/2026
The React Webcam WordPress plugin through 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.5)0.37%—Fabulatech Webcam FOR Remote Desktop6/3/202317/6/2026
A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42. It has been classified as problematic. Affected is the function 0x222018 in the library ftwebcam.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has…
ModificadaMedia (5.5)0.37%—Fabulatech Webcam FOR Remote Desktop6/3/202317/6/2026
A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This issue affects some unknown processing in the library ftwebcam.sys of the component Global Variable Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host.…
ModificadaMedia (5.5)0.37%—Fabulatech Webcam FOR Remote Desktop6/3/202317/6/2026
A vulnerability has been found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This vulnerability affects the function 0x222010/0x222018 in the library ftwebcam.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The…
ModificadaMedia (5.4)0.62%—Videowhisper Video Posts Webcam Recorder16/8/202117/6/2026
The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos.
ModificadaMedia (6.1)1.3%—Videowhisper Webcam31/1/202017/6/2026
Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhisper Webcam plugins for Drupal 7.x allows remote attackers to inject arbitrary web script or HTML via a URL to a crafted SVG file in the feed parameter.
ModificadaMedia (6.1)1.2%—Videowhisper Video Comments Webcam Recorder27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.
ModificadaCrítica (9.8)2.6%—Foscam C1 Webcam Firmware21/6/201717/6/2026
Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate device.
ModificadaMedia (4.3)1.6%—Videowhisper Video Posts Webcam Recorder2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder plugin 1.55.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.
ModificadaMedia (5)2.7%💥 ExploitSaschart Sascam Webcam Server28/6/201016/6/2026
Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash) via a large number of requests with a long line, as demonstrated using a long GET request.
ModificadaMedia (5)4.8%💥 ExploitTimhillone H264webcam21/6/201016/6/2026
H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)32%💥 ExploitSaschart Sascam Webcam Server5/8/200916/6/2026
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Get method and other unspecified methods.
ModificadaMedia (5)5.9%💥 ExploitWebcamxp6/1/200916/6/2026
Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the URI.
ModificadaAlta (9.4)4.5%💥 ExploitDarkwet Webcam XP19/12/200816/6/2026
Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and earlier allow remote attackers to cause a denial of service (device crash) and read portions of memory via (1) an invalid camnum parameter to the pocketpc component and (2) an invalid id parameter to…
ModificadaAlta (10)1.6%—Menalto Gallery Webcam Module17/1/200816/6/2026
Unspecified vulnerability in the WebCam module in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to a "proxied request."
ModificadaBaja (2.1)0.32%—Willings WebcamWillings Webcam Lite16/5/200516/6/2026
Willings WebCam and WebCam Lite 2.8 and earlier stores the password in memory in plaintext, which allows local users to gain sensitive information.
ModificadaMedia (4.3)1.2%—Webcamxp PRO2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in WebcamXP PRO v2.16.468 and earlier allows remote attackers to inject arbitrary web script or HTML via the chat name, as demonstrated by using an IFRAME to redirect users to other sites.
ModificadaMedia (5)2.6%—PY Software Active Webcam2/5/200516/6/2026
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service via a request to a file on the floppy drive, as demonstrated using A:\a.txt.
ModificadaMedia (5)1.5%—PY Software Active Webcam2/5/200516/6/2026
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to determine the existence of files via an HTTP request with a full pathname, which produces different messages whether the file exists or not.
Orbitaley — Vulnerabilidades