Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1654 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.38%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
AnalizadaAlta (7.5)0.50%—Apple IpadosApple Iphone OSApple MacosApple Visionos11/5/202617/6/2026
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able to track users through their IP address.
ModificadaAlta (7.5)0.54%—Apple IpadosApple Iphone OSApple MacosApple Tvos+111/5/202615/7/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
ModificadaAlta (7.5)0.54%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202615/7/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
ModificadaMedia (6.5)0.51%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202615/7/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
ModificadaMedia (6.5)0.51%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202615/7/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
ModificadaMedia (4.3)0.51%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202615/7/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
AnalizadaMedia (6.2)0.18%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A local user may be able to cause unexpected system termination or read…
ModificadaAlta (7.5)0.53%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202615/7/2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
AnalizadaAlta (7.5)0.50%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A local attacker may be able to modify the state of the Keychain.
ModificadaAlta (8.8)0.51%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202615/7/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
AnalizadaAlta (7.5)0.87%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/5/202617/6/2026
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected app termination.
Pendiente de análisisAlta (7.2)1.1%—Hikvision SwitchAI9/5/202624/7/2026
Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary…
Pendiente de análisisMedia (6.8)0.28%—Hikvision Hikcentral ProfessionalAI9/5/202625/7/2026
There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.
AplazadaAlta (8.8)1.2%—Geovision Gv-aswebAI6/5/202617/6/2026
A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server by sending a crafted HTTP POST request to the ASWebCommon.srf backend endpoint to bypass the frontend restrictions.
AnalizadaCrítica (9)0.75%—Geovision Gv-vms Firmware4/5/202617/6/2026
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. #### Stack-overflow via unconstrained sscanf The…
AnalizadaMedia (6.1)0.34%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS…
ModificadaCrítica (9.3)0.36%—Geovision Gv-ip Device Utility4/5/202617/6/2026
An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on…
ModificadaCrítica (9.8)1.00%—Geovision Gv-vms Firmware4/5/202617/6/2026
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
AplazadaCrítica (10)0.87%—Geovision Gv-vmsAI4/5/202617/6/2026
GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other security devices. It is a native application accessed locally, but it is also possible to enable remote access via the "WebCam Server" feature. Once enabled, it is possible to access to the management and…
ModificadaCrítica (9.9)0.62%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.
ModificadaMedia (6.5)0.50%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability.
AnalizadaMedia (6.1)0.34%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.
ModificadaAlta (7.5)0.57%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.
ModificadaAlta (8.8)3.3%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.