Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Wificam Wireless IP Camera (p2p) Firmware | 25/4/2017 | 17/6/2026 | Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pem inside the firmware, which allows attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Wificam Wireless IP Camera (p2p) Firmware | 25/4/2017 | 17/6/2026 | Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android application and a camera device, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (6.1) | 51% | 💥 Exploit | Axis Network Camera Firmware | 17/4/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. | |
| Modificada | Alta (8.8) | 2.6% | — | Dahuasecurity IP Camera Firmware | 30/3/2017 | 17/6/2026 | Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During exploitation, the first JSON object… | |
| Modificada | Alta (8.8) | 0.48% | — | Keekoonvision Kk002 IP Camera Firmware | 13/3/2017 | 17/6/2026 | Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entire set of other pages). | |
| Modificada | Alta (8.1) | 60% | — | Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware | 27/2/2017 | 17/6/2026 | The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding… | |
| Modificada | Crítica (9.8) | 13% | — | Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware | 27/2/2017 | 17/6/2026 | An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19. When SmartPSS Software is launched, while on the login screen, the software in the background automatically logs in as admin. This… | |
| Modificada | Media (5.9) | 8.9% | — | Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware | 27/2/2017 | 17/6/2026 | Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web Page, Mobile Application, and Desktop Application interfaces, which allows remote attackers to… | |
| Modificada | Alta (8.1) | 4.1% | — | Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware | 4/1/2017 | 17/6/2026 | NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain… | |
| Modificada | Crítica (9.8) | 5.2% | — | Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware | 4/1/2017 | 17/6/2026 | NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory… | |
| Modificada | Media (6.8) | 1.1% | — | Newphoria Corporation Auction Camera | 20/9/2015 | 17/6/2026 | The Newphoria Auction Camera application for iOS and before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors. | |
| Modificada | Media (5) | 2.4% | — | D-link Dcs-2103 HD Cube Network Camera Firmware | 3/12/2014 | 17/6/2026 | D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash) character. | |
| Modificada | Media (5) | 2.8% | — | D-link Dcs-2103 HD Cube Network Camera Firmware | 3/12/2014 | 17/6/2026 | Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (6.8) | 3.7% | — | Panasonic Network Camera Recorder Firmware | 17/10/2014 | 17/6/2026 | The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an arbitrary address. | |
| Modificada | Media (6.8) | 2.6% | — | Panasonic Network Camera View | 17/10/2014 | 17/6/2026 | Panasonic Network Camera View 3 and 4 allows remote attackers to execute arbitrary code via a crafted page, which triggers an invalid pointer dereference, related to "the ability to nullify an arbitrary address in memory." | |
| Modificada | Media (5.4) | 0.27% | — | Communityfactory Selfie Camera -facial Beauty- | 9/9/2014 | 17/6/2026 | The Selfie Camera -Facial Beauty- (aka com.cfinc.cunpic) application 1.2.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Fingersoft Cartoon Camera | 9/9/2014 | 17/6/2026 | The Cartoon Camera (aka com.fingersoft.cartooncamera) application 1.2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Americostech Selfshot Front Flash Camera | 9/9/2014 | 17/6/2026 | The Selfshot - Front Flash Camera (aka com.americos.selfshot) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.4) | 2.2% | — | Iodata Ts-wlcam/v Camera FirmwareIodata Ts-wlcam/v CameraIodata Ts-wptcam Camera FirmwareIodata Ts-wptcam Camera+8 | 29/7/2014 | 17/6/2026 | The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier, TS-WLCAM/V camera with firmware 1.06 and earlier, TS-WPTCAM camera with firmware 1.08 and earlier, TS-PTCAM camera with firmware 1.08 and earlier, TS-PTCAM/POE camera with firmware 1.08 and earlier, and TS-WLC2 camera with firmware 1.02 and earlier allow… | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Foscam IP Camera Firmware | 14/5/2014 | 17/6/2026 | Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifying arbitrary camera records in the Foscam DNS server. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Maygion IP Camera Firmware | 25/3/2014 | 16/6/2026 | Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in a GET request. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Maygion IP Camera Firmware | 25/3/2014 | 16/6/2026 | Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI. | |
| Modificada | Media (4.3) | 2.2% | — | Cisco Video Surveillance Indoor Fixed Dome IP HD Camera | 25/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCud10943 and CSCud10950. | |
| Modificada | Media (4.3) | 1.9% | — | Foscam Wireless IP Camera | 20/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web interface "WiFi scan" option in FOSCAM Wireless IP Cameras allows remote attackers to inject arbitrary web script or HTML via the SSID. | |
| Modificada | Media (6.4) | 1.2% | — | Cisco Video Surveillance 4000 IP CameraCisco Video Surveillance 4300e IP CameraCisco Video Surveillance 4500e IP Camera | 16/10/2013 | 16/6/2026 | The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419. |