Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

159 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.15%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an…
AplazadaAlta (8.6)0.20%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an…
AplazadaAlta (7.2)0.31%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device…
AplazadaAlta (7.2)0.31%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device…
AnalizadaCrítica (9.2)0.85%—Ptzoptics Pt12x-sdi-xx-g2 FirmwarePtzoptics Pt12x-ndi-xx FirmwarePtzoptics Pt12x-usb-xx-g2 FirmwarePtzoptics Pt20x-sdi-xx-g2 Firmware+575/9/202517/6/2026
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.
AnalizadaCrítica (9.3)0.77%—Ptzoptics Pt12x-sdi-xx-g2 FirmwarePtzoptics Pt12x-ndi-xx FirmwarePtzoptics Pt12x-usb-xx-g2 FirmwarePtzoptics Pt20x-sdi-xx-g2 Firmware+475/9/202517/6/2026
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.
ModificadaMedia (4.4)0.18%—Fortinet Forticamera FirmwareFortinet FortimailFortinet FortindrFortinet Fortirecorder+112/8/202517/6/2026
Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions,…
ModificadaAlta (7.8)0.15%💥 PoCAziot 2MP Full HD Smart Wi-fi Cctv Home Security Camera Firmware30/7/20255/7/2026
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in…
AnalizadaCrítica (9.8)30%⚠ Explotación activa💥 PoCFortinet FortimailFortinet FortindrFortinet FortirecorderFortinet Fortivoice+113/5/202517/6/2026
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0,…
AnalizadaAlta (7.7)0.58%—LSC PTZ Dual Band Camera Firmware11/3/202517/6/2026
LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.
AnalizadaCrítica (9.8)1.1%—Vivotek Camera Firmware29/2/202417/6/2026
An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component.
ModificadaCrítica (9.8)0.60%—Milesight Ncr/camera Firmware12/6/202317/6/2026
Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.
ModificadaAlta (8.8)1.00%—Furbo DOG Camera Firmware2/6/202317/6/2026
Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated remote attacker in the Bluetooth network with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands or disrupt service.
ModificadaCrítica (9.8)4.2%—Uniview Camera Firmware31/5/202317/6/2026
Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve code execution. By using this buffer…
ModificadaCrítica (9.8)1.8%—Flir Dvtel Camera Firmware15/5/202317/6/2026
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.
ModificadaCrítica (9.8)1.9%—Agasio Camera Project Agasio Camera Firmware15/5/202317/6/2026
An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters.
ModificadaAlta (7.5)0.57%—Milesight Ncr/camera Firmware8/5/202317/6/2026
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
ModificadaAlta (7.5)0.50%—Milesight Ncr/camera Firmware8/5/202317/6/2026
Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.
ModificadaAlta (7.5)0.59%—Biltema Baby Camera FirmwareBiltema IP Camera Firmware3/2/202317/6/2026
Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive information.
ModificadaAlta (8.8)1.1%—Mipcm Mipc Camera Firmware26/9/202217/6/2026
Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2003161406.
ModificadaAlta (8.8)2.5%—Mipcm Mipc Camera Firmware26/9/202217/6/2026
Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remote code execution on cameras running the firmware when a victim logs into a specially crafted mobile app.
ModificadaMedia (6.5)0.71%—Cellinx NVT - IP PTZ Camera Firmware18/7/202217/6/2026
Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS as root user.
ModificadaAlta (8.8)0.54%—Cellinx NVT - IP PTZ Camera Firmware18/7/202217/6/2026
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.
ModificadaAlta (7.5)3.7%💥 PoCNetwavepr Indoor IP Camera FirmwareNetwavepr Outdoor IP Camera Firmware10/6/202217/6/2026
There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).
ModificadaMedia (5.3)0.69%—Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+1712/11/202117/6/2026
An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware.
Orbitaley — Vulnerabilidades