Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.3%💥 ExploitWificam Wireless IP Camera (p2p) Firmware25/4/201717/6/2026
Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pem inside the firmware, which allows attackers to obtain sensitive information.
ModificadaAlta (7.5)2.7%💥 ExploitWificam Wireless IP Camera (p2p) Firmware25/4/201717/6/2026
Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android application and a camera device, which allows remote attackers to obtain sensitive information by sniffing the network.
ModificadaMedia (6.1)51%💥 ExploitAxis Network Camera Firmware17/4/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
ModificadaAlta (8.8)2.6%—Dahuasecurity IP Camera Firmware30/3/201717/6/2026
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During exploitation, the first JSON object…
ModificadaAlta (8.8)0.48%—Keekoonvision Kk002 IP Camera Firmware13/3/201717/6/2026
Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entire set of other pages).
ModificadaAlta (8.1)60%—Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware27/2/201717/6/2026
The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding…
ModificadaCrítica (9.8)13%—Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware27/2/201717/6/2026
An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19. When SmartPSS Software is launched, while on the login screen, the software in the background automatically logs in as admin. This…
ModificadaMedia (5.9)8.9%—Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware27/2/201717/6/2026
Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web Page, Mobile Application, and Desktop Application interfaces, which allows remote attackers to…
ModificadaAlta (8.1)4.1%—Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware4/1/201717/6/2026
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain…
ModificadaCrítica (9.8)5.2%—Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware4/1/201717/6/2026
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory…
ModificadaMedia (6.8)1.1%—Newphoria Corporation Auction Camera20/9/201517/6/2026
The Newphoria Auction Camera application for iOS and before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.
ModificadaMedia (5)2.4%—D-link Dcs-2103 HD Cube Network Camera Firmware3/12/201417/6/2026
D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash) character.
ModificadaMedia (5)2.8%—D-link Dcs-2103 HD Cube Network Camera Firmware3/12/201417/6/2026
Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
ModificadaMedia (6.8)3.7%—Panasonic Network Camera Recorder Firmware17/10/201417/6/2026
The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an arbitrary address.
ModificadaMedia (6.8)2.6%—Panasonic Network Camera View17/10/201417/6/2026
Panasonic Network Camera View 3 and 4 allows remote attackers to execute arbitrary code via a crafted page, which triggers an invalid pointer dereference, related to "the ability to nullify an arbitrary address in memory."
ModificadaMedia (5.4)0.27%—Communityfactory Selfie Camera -facial Beauty-9/9/201417/6/2026
The Selfie Camera -Facial Beauty- (aka com.cfinc.cunpic) application 1.2.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Fingersoft Cartoon Camera9/9/201417/6/2026
The Cartoon Camera (aka com.fingersoft.cartooncamera) application 1.2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Americostech Selfshot Front Flash Camera9/9/201417/6/2026
The Selfshot - Front Flash Camera (aka com.americos.selfshot) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.4)2.2%—Iodata Ts-wlcam/v Camera FirmwareIodata Ts-wlcam/v CameraIodata Ts-wptcam Camera FirmwareIodata Ts-wptcam Camera+829/7/201417/6/2026
The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier, TS-WLCAM/V camera with firmware 1.06 and earlier, TS-WPTCAM camera with firmware 1.08 and earlier, TS-PTCAM camera with firmware 1.08 and earlier, TS-PTCAM/POE camera with firmware 1.08 and earlier, and TS-WLC2 camera with firmware 1.02 and earlier allow…
ModificadaAlta (10)12%💥 ExploitFoscam IP Camera Firmware14/5/201417/6/2026
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifying arbitrary camera records in the Foscam DNS server.
ModificadaAlta (7.5)12%💥 ExploitMaygion IP Camera Firmware25/3/201416/6/2026
Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in a GET request.
ModificadaMedia (5)3.5%💥 ExploitMaygion IP Camera Firmware25/3/201416/6/2026
Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.
ModificadaMedia (4.3)2.2%—Cisco Video Surveillance Indoor Fixed Dome IP HD Camera25/1/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCud10943 and CSCud10950.
ModificadaMedia (4.3)1.9%—Foscam Wireless IP Camera20/11/201316/6/2026
Cross-site scripting (XSS) vulnerability in the web interface "WiFi scan" option in FOSCAM Wireless IP Cameras allows remote attackers to inject arbitrary web script or HTML via the SSID.
ModificadaMedia (6.4)1.2%—Cisco Video Surveillance 4000 IP CameraCisco Video Surveillance 4300e IP CameraCisco Video Surveillance 4500e IP Camera16/10/201316/6/2026
The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419.
Orbitaley — Vulnerabilidades