Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
389 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.73% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi password. This application is installed on the device… | |
| Modificada | Media (6.5) | 1.6% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car garages, and also in… | |
| Modificada | Alta (7.8) | 0.73% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi name. This application is installed on the device and an… | |
| Modificada | Media (6.5) | 2.1% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has default Wi-Fi credentials that are exactly the same for every device. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and… | |
| Modificada | Media (6.5) | 1.9% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that any malicious user connecting to the device can change the default SSID and password thereby denying the owner an access to his/her own device. This device acts as an Endoscope camera that allows… | |
| Modificada | Crítica (9.8) | 6.8% | — | Goahead Wireless IP Camera Wificam Firmware | 11/6/2019 | 17/6/2026 | An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI. | |
| Modificada | Alta (7.5) | 1.4% | — | Securitycamera Security Camera CZ | 7/6/2019 | 17/6/2026 | The Security Camera CZ application through 1.6.8 for Android stores potentially sensitive recorded video in external data storage, which is readable by any application. | |
| Modificada | Crítica (9.8) | 56% | 💥 Exploit | Barni Master IP Camera01 Firmware | 8/5/2019 | 17/6/2026 | MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. | |
| Modificada | Baja (3.3) | 0.27% | — | Bosch Smart Camera | 22/2/2019 | 17/6/2026 | An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to setting of insecure permissions, a malicious app could potentially succeed in retrieving video clips or still images that have been cached for clip sharing. (The Bosch Smart Home App is not affected. iOS Apps are not affected.) | |
| Modificada | Alta (7.5) | 0.48% | — | Bosch Smart Camera | 22/2/2019 | 17/6/2026 | An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to improperly implemented TLS certificate checks, a malicious actor could potentially succeed in executing a man-in-the-middle attack for some connections. (The Bosch Smart Home App is not affected. iOS Apps are not affected.) | |
| Modificada | Media (6.1) | 0.80% | — | Vivotek Camera | 3/1/2019 | 17/6/2026 | Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header. | |
| Modificada | Media (6.1) | 0.80% | — | Vivotek Camera | 3/1/2019 | 17/6/2026 | Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript via a URL query string parameter. | |
| Modificada | Media (5.3) | 0.93% | — | Vivotek Camera | 3/1/2019 | 17/6/2026 | Incorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a allows remote attackers to enable arbitrary system services via a URL parameter. | |
| Modificada | Crítica (9.8) | 1.4% | — | Guardzilla 360 Outdoor FirmwareGuardzilla 180 Outdoor FirmwareGuardzilla 360 Indoor FirmwareGuardzilla 180 Indoor Firmware+2 | 31/12/2018 | 17/6/2026 | The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring. | |
| Modificada | Alta (7) | 0.63% | — | Mydlink Baby Camera MonitorD-link Dcs-825l Firmware | 20/12/2018 | 17/6/2026 | An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and password) in base64 cleartext. An attacker… | |
| Modificada | Crítica (9.8) | 1.9% | — | Bosch 360-indoor Camera FirmwareBosch Eyes Outdoor Camera Firmware | 19/12/2018 | 17/6/2026 | An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there is a buffer overflow in the RCP+ parser… | |
| Modificada | Alta (7.5) | 1.4% | — | Qacctv Jooan Ja-q1h Wi-fi Camera Firmware | 10/12/2018 | 17/6/2026 | Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via certain ONVIF methods such as CreateUsers, SetImagingSettings, GetStreamUri, and so on. | |
| Modificada | Alta (7.5) | 1.5% | — | Qacctv Jooan Ja-q1h Wi-fi Camera Firmware | 10/12/2018 | 17/6/2026 | Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via the ONVIF GetStreamUri method and GetVideoEncoderConfigurationOptions method. | |
| Modificada | Alta (7.5) | 2.3% | — | Yitechnology YI Home Camera FirmwareYitechnology YI Home | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can allocate unlimited memory, resulting in denial of service. An attacker can send a set of packets to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 2.6% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a logic flaw, resulting in an authentication bypass. An attacker can sniff network traffic and send a set of packets to trigger this vulnerability. | |
| Modificada | Media (6.8) | 0.59% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7.0D. A specially crafted 7-Zip file can cause a CRC collision, resulting in a firmware update and code execution. An attacker can insert an SDcard to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.9% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return… | |
| Modificada | Alta (7.5) | 1.9% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return… | |
| Modificada | Alta (8.1) | 2.7% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted packet can cause a buffer overflow, resulting in code execution. An attacker can intercept and alter network traffic to trigger this vulnerability. | |
| Modificada | Media (4.6) | 0.40% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw, resulting in a firmware downgrade. An attacker can insert an SD card to trigger this vulnerability. |