Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Uniview Ipc322lb-sf28-a Firmware | 19/9/2023 | 17/6/2026 | The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability could allow the… | |
| Modificada | Alta (8.8) | 17% | — | Advantech Iview | 31/7/2023 | 17/6/2026 | An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection. | |
| Modificada | Media (6.1) | 0.59% | — | Sophos Iview | 5/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed. | |
| Modificada | Crítica (9.8) | 4.2% | — | Uniview Camera Firmware | 31/5/2023 | 17/6/2026 | Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve code execution. By using this buffer… | |
| Modificada | Alta (7.5) | 29% | — | Advantech Iview | 27/9/2022 | 17/6/2026 | An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in… | |
| Modificada | Crítica (9.8) | 59% | 💥 Exploit | Advantech Iview | 22/7/2022 | 17/6/2026 | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. | |
| Modificada | Media (5.9) | 0.89% | — | Advantech Iview | 22/7/2022 | 17/6/2026 | The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attacker to disclose information. | |
| Modificada | Crítica (9.8) | 16% | — | Advantech Iview | 22/7/2022 | 17/6/2026 | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code. | |
| Modificada | Alta (7.5) | 11% | — | Advantech Iview | 22/7/2022 | 17/6/2026 | The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition. | |
| Modificada | Media (4.9) | 0.94% | — | Advantech Iview | 22/7/2022 | 17/6/2026 | The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information | |
| Modificada | Media (6.5) | 9.1% | — | Advantech Iview | 22/7/2022 | 17/6/2026 | The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information. | |
| Modificada | Alta (7.5) | 10% | — | Advantech Iview | 22/7/2022 | 17/6/2026 | The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information. | |
| Modificada | Alta (7.5) | 1.2% | — | Advantech Iview | 11/6/2021 | 17/6/2026 | The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182). | |
| Modificada | Crítica (9.8) | 8.1% | — | Advantech Iview | 11/6/2021 | 17/6/2026 | The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (versions prior to v5.7.03.6182). | |
| Modificada | Crítica (9.8) | 1.1% | — | Uniview Isc2500-s Firmware | 29/4/2021 | 17/6/2026 | An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious code via /Interface/DevManage/EC.php?cmd=upload | |
| Modificada | Crítica (9.8) | 13% | — | Advantech Iview | 11/2/2021 | 17/6/2026 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'. | |
| Modificada | Alta (7.5) | 3.2% | — | Advantech Iview | 11/2/2021 | 17/6/2026 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files. | |
| Modificada | Alta (7.5) | 12% | — | Advantech Iview | 11/2/2021 | 17/6/2026 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information. | |
| Modificada | Crítica (9.8) | 37% | 💥 Exploit | Advantech Iview | 11/2/2021 | 17/6/2026 | Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution. | |
| Modificada | Crítica (9.8) | 7.7% | — | Advantech Iview | 25/8/2020 | 17/6/2026 | Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code. | |
| Modificada | Crítica (9.8) | 3.5% | — | Advantech Iview | 15/7/2020 | 17/6/2026 | Advantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this vulnerability could allow an attacker to remotely execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.7% | — | Advantech Iview | 15/7/2020 | 17/6/2026 | Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulnerability may allow an attacker to obtain the information of the user table, including the administrator credentials in plain text. An attacker may also delete the… | |
| Modificada | Alta (7.5) | 1.7% | — | Advantech Iview | 15/7/2020 | 17/6/2026 | Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials. | |
| Modificada | Crítica (9.8) | 4.9% | — | Advantech Iview | 15/7/2020 | 17/6/2026 | Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code. | |
| Modificada | Crítica (9.8) | 7.0% | — | Advantech Iview | 15/7/2020 | 17/6/2026 | Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker… |