Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.15% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an… | |
| Aplazada | Alta (8.6) | 0.20% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an… | |
| Aplazada | Alta (7.2) | 0.31% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device… | |
| Aplazada | Alta (7.2) | 0.31% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device… | |
| Analizada | Crítica (9.2) | 0.85% | — | Ptzoptics Pt12x-sdi-xx-g2 FirmwarePtzoptics Pt12x-ndi-xx FirmwarePtzoptics Pt12x-usb-xx-g2 FirmwarePtzoptics Pt20x-sdi-xx-g2 Firmware+57 | 5/9/2025 | 17/6/2026 | PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface. | |
| Analizada | Crítica (9.3) | 0.77% | — | Ptzoptics Pt12x-sdi-xx-g2 FirmwarePtzoptics Pt12x-ndi-xx FirmwarePtzoptics Pt12x-usb-xx-g2 FirmwarePtzoptics Pt20x-sdi-xx-g2 Firmware+47 | 5/9/2025 | 17/6/2026 | PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user. | |
| Modificada | Media (4.4) | 0.18% | — | Fortinet Forticamera FirmwareFortinet FortimailFortinet FortindrFortinet Fortirecorder+1 | 12/8/2025 | 17/6/2026 | Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions,… | |
| Modificada | Alta (7.8) | 0.15% | — | Aziot 2MP Full HD Smart Wi-fi Cctv Home Security Camera Firmware | 30/7/2025 | 5/7/2026 | The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in… | |
| Analizada | Crítica (9.8) | 30% | ⚠ Explotación activa | Fortinet FortimailFortinet FortindrFortinet FortirecorderFortinet Fortivoice+1 | 13/5/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0,… | |
| Analizada | Alta (7.7) | 0.58% | — | LSC PTZ Dual Band Camera Firmware | 11/3/2025 | 17/6/2026 | LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera. | |
| Analizada | Crítica (9.8) | 1.1% | — | Vivotek Camera Firmware | 29/2/2024 | 17/6/2026 | An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component. | |
| Modificada | Crítica (9.8) | 0.60% | — | Milesight Ncr/camera Firmware | 12/6/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method. | |
| Modificada | Alta (8.8) | 1.00% | — | Furbo DOG Camera Firmware | 2/6/2023 | 17/6/2026 | Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated remote attacker in the Bluetooth network with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands or disrupt service. | |
| Modificada | Crítica (9.8) | 4.2% | — | Uniview Camera Firmware | 31/5/2023 | 17/6/2026 | Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve code execution. By using this buffer… | |
| Modificada | Crítica (9.8) | 1.8% | — | Flir Dvtel Camera Firmware | 15/5/2023 | 17/6/2026 | An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device. | |
| Modificada | Crítica (9.8) | 1.9% | — | Agasio Camera Project Agasio Camera Firmware | 15/5/2023 | 17/6/2026 | An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters. | |
| Modificada | Alta (7.5) | 0.57% | — | Milesight Ncr/camera Firmware | 8/5/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request. | |
| Modificada | Alta (7.5) | 0.50% | — | Milesight Ncr/camera Firmware | 8/5/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request. | |
| Modificada | Alta (7.5) | 0.59% | — | Biltema Baby Camera FirmwareBiltema IP Camera Firmware | 3/2/2023 | 17/6/2026 | Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive information. | |
| Modificada | Alta (8.8) | 1.1% | — | Mipcm Mipc Camera Firmware | 26/9/2022 | 17/6/2026 | Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2003161406. | |
| Modificada | Alta (8.8) | 2.5% | — | Mipcm Mipc Camera Firmware | 26/9/2022 | 17/6/2026 | Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remote code execution on cameras running the firmware when a victim logs into a specially crafted mobile app. | |
| Modificada | Media (6.5) | 0.71% | — | Cellinx NVT - IP PTZ Camera Firmware | 18/7/2022 | 17/6/2026 | Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS as root user. | |
| Modificada | Alta (8.8) | 0.54% | — | Cellinx NVT - IP PTZ Camera Firmware | 18/7/2022 | 17/6/2026 | On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera. | |
| Modificada | Alta (7.5) | 3.7% | — | Netwavepr Indoor IP Camera FirmwareNetwavepr Outdoor IP Camera Firmware | 10/6/2022 | 17/6/2026 | There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password). | |
| Modificada | Media (5.3) | 0.69% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware. |