Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1654 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.45% | — | Geovision VMSAIGeovision GV CloudAIGeovision GeowebplayerAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision SoftwareAIGeovision Gv-vmsAIGeovision Gv-cloudAIGeovision GeowebplayerAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.8) | 0.38% | — | Geovision GeowebplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Media (6.4) | 0.35% | — | Foliovision FV Flowplayer Video PlayerAI | 1/7/2026 | 1/7/2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (5.3) | 0.34% | — | Cvat Computer Vision Annotation Tool | 30/6/2026 | 14/7/2026 | CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the parent_id query parameter of the quality… | |
| Aplazada | Crítica (9.8) | 0.65% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this vulnerability by sending crafted login data with… | |
| Aplazada | Crítica (9.8) | 0.95% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this vulnerability by sending a crafted RTSP… | |
| Aplazada | Crítica (9.8) | 0.95% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this vulnerability by sending a crafted RTSP… | |
| Aplazada | Crítica (9.8) | 0.95% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AIThttpdAI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by… | |
| Aplazada | Alta (8.6) | 0.43% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by… | |
| Aplazada | Alta (7.5) | 0.55% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing HTTP request body data. A remote attacker may exploit this vulnerability by sending a crafted request with… | |
| Aplazada | Alta (7.5) | 0.73% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of required HTTP request metadata before it is used by the affected components. A… | |
| Aplazada | Alta (7.5) | 0.55% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing filename values in multipart upload data. A remote attacker may exploit this vulnerability by sending a… | |
| Aplazada | Alta (7.5) | 0.35% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of multipart upload headers when processing certificate-related upload fields. A remote attacker may exploit this… | |
| Aplazada | Alta (7.5) | 1.5% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI component. A remote attacker may exploit this… | |
| Aplazada | Crítica (9.1) | 2.7% | — | Geovision Gv-i O BOX 4EAI | 24/6/2026 | 25/6/2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various… | |
| Aplazada | Crítica (9.1) | 2.7% | — | Geovision Gv-i/o BOX 4EAI | 24/6/2026 | 25/6/2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various… | |
| Aplazada | Crítica (9.1) | 2.7% | — | Geovision Gv-i/o BOX 4EAI | 24/6/2026 | 25/6/2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various… | |
| Aplazada | Crítica (10) | 0.60% | — | Geovision Gv-i O BOX 4EAI | 24/6/2026 | 25/6/2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a… | |
| Aplazada | Media (6.2) | 0.34% | — | Geovision Gv-vmsAI | 24/6/2026 | 25/6/2026 | A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted network request can lead to a denial of service. An attacker can impersonate the legitimate server to trigger this vulnerability. |