Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.2% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary characters in the pureftpd.passwd file during a username change, which in turn allows for bypassing chroot restrictions in the FTP server. An… | |
| Modificada | Alta (8.8) | 4.3% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during NTP server configuration resulting in command injection. An attacker can simply send an HTTP request to the device to… | |
| Modificada | Alta (8.8) | 4.1% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to… | |
| Modificada | Alta (8.8) | 4.1% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to… | |
| Modificada | Alta (8.8) | 4.1% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to… | |
| Modificada | Alta (8.8) | 6.5% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during the SMTP configuration tests resulting in command… | |
| Modificada | Alta (8.8) | 3.5% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger… | |
| Modificada | Alta (8.8) | 3.4% | — | Foscam C1 Indoor HD Camera Firmware | 27/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger… | |
| Modificada | Alta (8.8) | 3.4% | — | Foscam C1 Indoor HD Camera Firmware | 27/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger… | |
| Modificada | Alta (8.8) | 5.4% | — | Foscam C1 Indoor HD Camera Firmware | 27/6/2017 | 17/6/2026 | An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An… | |
| Modificada | Alta (7.5) | 69% | — | Vivotek Network Camera Ib8369 FirmwareVivotek Network Camera Fd8164 FirmwareVivotek Network Camera Fd816ba Firmware | 23/6/2017 | 17/6/2026 | '/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnerability is already verified on VIVOTEK Network Camera… | |
| Modificada | Crítica (9.8) | 82% | — | Vivotek Network Camera Ib8369 FirmwareVivotek Network Camera Fd8164 FirmwareVivotek Network Camera Fd816ba Firmware | 23/6/2017 | 17/6/2026 | '/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most… | |
| Modificada | Alta (7.5) | 2.8% | — | Foscam C1 Indoor HD Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the… | |
| Modificada | Alta (7.5) | 2.8% | — | Foscam C1 Indoor HD Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the… | |
| Modificada | Media (6.5) | 2.9% | — | Foscam C1 Indoor HD Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause the application to read a file from disk but a failure to adequately filter characters results in allowing an… | |
| Modificada | Alta (8.8) | 7.9% | — | Foscam C1 Indoor HD Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An… | |
| Modificada | Alta (8.8) | 7.9% | — | Foscam C1 Indoor HD Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An… | |
| Modificada | Crítica (9.8) | 26% | — | Foscam C1 HD Indoor Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the stack frame. An attacker can simply send an http request to the… | |
| Modificada | Crítica (9.8) | 52% | 💥 Exploit | Geutebruck IP Camera G-cam Efd-2250 Firmware | 19/5/2017 | 17/6/2026 | An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attackers to bypass the access control that may allow remote code execution. | |
| Modificada | Crítica (9.8) | 30% | 💥 Exploit | Geutebrueck IP Camera G-cam Efd-2250 Firmware | 19/5/2017 | 17/6/2026 | An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters… | |
| Modificada | Alta (8.8) | 18% | 💥 Exploit | Axis Network Camera Firmware | 2/5/2017 | 17/6/2026 | The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml. | |
| Modificada | Alta (8.8) | 0.81% | — | 360fly 4K Camera Firmware | 1/5/2017 | 17/6/2026 | 360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password. This affects firmware 2.1.4. Exploitation can use the 360fly Android or iOS application, or the BlueZ… | |
| Modificada | Crítica (9.8) | 35% | 💥 Exploit | Wificam Wireless IP Camera (p2p) Firmware | 25/4/2017 | 17/6/2026 | On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI. | |
| Modificada | Crítica (9.8) | 8.7% | 💥 Exploit | Wificam Wireless IP Camera (p2p) Firmware | 25/4/2017 | 17/6/2026 | Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Wificam Wireless IP Camera (p2p) Firmware | 25/4/2017 | 17/6/2026 | On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0. |