Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.98%—Camera Life8/8/200716/6/2026
Multiple unspecified vulnerabilities in Camera Life before 2.6 allow attackers to cause a denial of service via unknown vectors.
ModificadaAlta (10)16%💥 ExploitSony Network Camera Snc-p529/6/200716/6/2026
Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N and SNC-DF70N before 1.18; SNC-RZ50N and SNC-CS50N before 2.22; SNC-DF85N, SNC-DF80N, and SNC-DF50N before 1.12; and SNC-RX570N/W,…
ModificadaMedia (4.3)1.2%—Canon Network Camera Server Vb100Canon Network Camera Server Vb101Canon Network Camera Server Vb15015/5/200716/6/2026
Cross-site scripting (XSS) vulnerability in the management interface in Canon Network Camera Server VB100 and VB101 with firmware 3.0 R69 and earlier, and VB150 with firmware 1.1 R39 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)12%💥 ExploitAxis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+67/5/200716/6/2026
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer…
ModificadaMedia (5)21%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb1012/3/200716/6/2026
Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
ModificadaMedia (5.8)2.0%💥 ExploitSeyeon Flexwatch Network Camera18/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL.
ModificadaAlta (7.5)3.1%💥 ExploitSeyeon Flexwatch Network Camera18/7/200616/6/2026
Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot) and encoded / (%2f) sequence in the URL.
ModificadaMedia (5)17%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb1016/7/200616/6/2026
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference.
ModificadaMedia (4)13%—Microsoft IECanon Network Camera Server Vb1017/6/200616/6/2026
Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file…
ModificadaMedia (4.3)2.9%💥 ExploitMobotix IP Network Camera19/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to inject arbitrary web script or HTML via URL-encoded values in (1) the query string to help/help, (2) the…
ModificadaAlta (7.5)70%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10111/4/200616/6/2026
Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.
ModificadaBaja (2.6)32%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10111/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability." NOTE: this is…
ModificadaAlta (7.5)58%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10111/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.
ModificadaAlta (7.5)11%—Microsoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10131/12/200516/6/2026
Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method…
ModificadaAlta (10)5.4%—Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+1031/12/200416/6/2026
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system information via (5) setparam.cgi and (6)…
ModificadaAlta (7.5)14%💥 ExploitAxis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+1031/12/200416/6/2026
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.
ModificadaMedia (5)2.8%💥 PoCDelegateDnrdDON Moore MydnsMaradns+1131/12/200416/6/2026
Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by…
ModificadaMedia (5)4.2%—Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+1031/12/200416/6/2026
Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using…
ModificadaAlta (7.5)3.2%💥 ExploitD-link Dcs-900 Internet Camera31/8/200416/6/2026
D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.
ModificadaAlta (10)30%💥 ExploitAxis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+59/6/200316/6/2026
The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).
ModificadaAlta (7.5)2.4%—Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis Neteye 200+131/12/200116/6/2026
Axis network camera 2120, 2110, 2100, 200+ and 200 contains a default administration password "pass", which allows remote attackers to gain access to the camera.
Orbitaley — Vulnerabilidades