Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

389 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.28%—Kenik Camera Management PanelAIKenik Kg-5260xxxx-il- G 2AI25/5/202623/7/2026
Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file path and read corresponding files located on the server. The issue was fixed in version 2026-04-23 of the KG-5260xxxx-IL-(G)2 cameras. Rest of the products were fixed in…
AplazadaMedia (5.2)0.13%—CP Plus Wi-fi CameraAI25/5/202623/7/2026
This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private…
AplazadaCrítica (9.1)0.59%—Zkteco Cctv CamerasAI20/5/202620/7/2026
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.
Pendiente de análisisAlta (7.3)1.5%—Milesight Camera FirmwareAI28/4/202625/7/2026
A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.
Pendiente de análisisCrítica (9.2)0.39%—Milesight Aiot CamerasAI28/4/202625/7/2026
Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
Pendiente de análisisAlta (8.6)0.29%—Milesight Aiot Camera FirmwareAI28/4/202620/7/2026
An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
Pendiente de análisisAlta (7.7)0.35%—Milesight Aiot Camera FirmwareAI28/4/202625/7/2026
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
Pendiente de análisisAlta (7.3)0.28%—Milesight Aiot CamerasAI27/4/202625/7/2026
A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.
AnalizadaMedia (5.1)0.08%—Samsung Camera13/4/202617/6/2026
Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability.
Pendiente de análisisAlta (7.2)0.54%—LSC Indoor CameraAI27/3/202617/6/2026
A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application fails to validate the length of the Protocol parameter inside the Transport element. By sending a specially crafted SOAP request containing an oversized protocol string, an attacker can overflow the…
Pendiente de análisisAlta (7.2)0.33%—LSC Smart Indoor IP CameraAI25/3/202617/6/2026
A buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handling of the Time Zone (TZ) parameter within the ONVIF configuration interface. The time zone (TZ) parameter does not have its length properly validated before being copied into a fixed-size buffer…
AplazadaAlta (8.2)0.29%—Yitechnology YI Home Camera 2AI20/3/202617/6/2026
A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This impacts an unknown function of the file home/web/ipc of the component HTTP Firmware Update Handler. The manipulation leads to improper verification of cryptographic signature. The attack is possible to be carried out remotely.…
AplazadaBaja (1.3)0.25%—Yitechnology YI Home Camera 2AI20/3/202617/6/2026
A vulnerability was determined in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This affects an unknown function of the component WPA/WPS. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack can only be done within the local network. This attack is characterized by high…
AplazadaBaja (2.1)0.40%—Yitechnology YI Home Camera 2AI20/3/202617/6/2026
A vulnerability was found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The impacted element is an unknown function of the file home/web/ipc of the component CGI Endpoint. Performing a manipulation results in missing authentication. Access to the local network is required for this attack. The exploit has…
AplazadaAlta (7.4)0.48%—Yitechnology YI Home Camera 2AI20/3/202617/6/2026
A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknown function of the file home/web/ipc. Such manipulation leads to hard-coded credentials. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the…
AnalizadaAlta (7.7)0.23%—Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+1013/2/202617/6/2026
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel.…
AnalizadaBaja (2)0.36%—Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+1013/2/202617/6/2026
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow…
AnalizadaMedia (5.7)0.18%—Axis Camera Station PRO10/2/202617/6/2026
An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.
AnalizadaMedia (4.5)0.23%—Axis Camera Station PRO10/2/202617/6/2026
A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.
AnalizadaMedia (4.6)0.26%—Axis Camera Station PRO10/2/202617/6/2026
An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.
AnalizadaAlta (7.8)0.16%—Axis Camera Station PRO10/2/202617/6/2026
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
AplazadaAlta (8.7)0.45%—Dbpower C300 HD CameraAI7/2/202617/6/2026
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the…
AplazadaAlta (8.7)0.47%—ACE Security Wip-90113 HD CameraAI7/2/202617/6/2026
ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint, exposing credentials and system…
AplazadaAlta (8.7)1.2%—Meritlilin IP CameraAI12/1/202617/6/2026
Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
AplazadaCrítica (9.3)12%—Flir Thermal Camera Pt-series FirmwareAI8/1/202617/6/2026
FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerFlirSystem.php script. Attackers can execute arbitrary system commands as root by exploiting unsanitized POST parameters in the execFlirSystem() function through…