Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

389 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)16%—Flir Thermal Camera Fc-s/ptAI8/1/202617/6/2026
FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 contains an authenticated OS command injection vulnerability that allows attackers to execute shell commands with root privileges. Authenticated attackers can inject arbitrary shell commands through unvalidated input parameters to gain complete control of the…
AplazadaCrítica (9.3)0.33%—Flir Thermal Camera FirmwareAI8/1/202617/6/2026
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains hard-coded SSH credentials that cannot be changed through normal camera operations. Attackers can leverage these persistent, unmodifiable credentials to gain unauthorized remote access to the thermal camera system.
AplazadaAlta (8.7)0.47%—Flir Thermal Camera F FC PT D Stream FirmwareAI8/1/202617/6/2026
FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows remote attackers to access live camera streams without credentials. Attackers can exploit the vulnerability to view unauthorized thermal camera video feeds across multiple camera series without…
AplazadaAlta (8.7)9.5%—Flir Thermal Camera F/fc/pt/dAI8/1/202617/6/2026
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files…
AplazadaAlta (8.7)0.47%—Flir Thermal Traffic CamerasAI24/12/202517/6/2026
FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming URLs without authentication.
AplazadaCrítica (9.3)0.33%—Flir Thermal Traffic CamerasAI24/12/202517/6/2026
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of…
AnalizadaAlta (8.8)0.34%—LSC Smart Connect Indoor IP Camera Firmware22/12/202517/6/2026
LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.
AplazadaAlta (7)0.19%—Tp-link TapoAITp-link Tapo CameraAI16/12/202517/6/2026
Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo cameras, allowing attackers to brute force the password in the local network. Issue can be mitigated through mobile application updates. Device firmware remains unchanged.
AnalizadaAlta (7.5)0.19%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer.
AnalizadaMedia (6.5)0.28%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.
AnalizadaAlta (8.1)0.23%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate firmware signatures during updates, uses outdated cryptographic…
AnalizadaCrítica (9.8)0.98%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.
AnalizadaMedia (6.6)1.1%—Aqara Camera HUB G3 Firmware10/12/202525/9/2026
Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.
AnalizadaAlta (7.3)0.80%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.
AnalizadaAlta (7.4)0.18%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device control and monitoring.
AnalizadaAlta (7.4)0.18%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potentially serve modified firmware files.
AplazadaAlta (8.7)0.94%—JVC Vn-t IP CameraAI12/11/202517/6/2026
JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.
ModificadaAlta (7.5)0.48%—Simicam IP Camera FirmwareKeview IP Camera FirmwareAsecam IP Camera Firmware12/11/202517/6/2026
Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication.
AplazadaAlta (7.1)0.26%—Ubia CameraAI6/11/202517/6/2026
The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of settings.
AplazadaCrítica (9.3)0.46%—Survision LPR CameraAI4/11/202517/6/2026
The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration wizard immediately without a login prompt or credentials check.
AplazadaMedia (6.8)0.23%—Honeywell S35 Series CamerasAI27/10/202517/6/2026
Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeywell also recommends updating to the most recent version of this product, service…
AplazadaMedia (6.8)0.14%—Nous W3 Smart Wifi CameraAI24/10/20255/7/2026
An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically proximate attackers to escalate privileges to root via supplying a crafted update.tar archive file stored on a FAT32-formatted SD card.
AnalizadaBaja (0.3)0.16%—Furbo Mini FirmwareFurbo 360 DOG Camera Firmware12/10/202517/6/2026
A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the file /etc/shadow of the component Password Handler. Executing manipulation can lead to use of weak hash. The physical device can be targeted for the attack. The attack requires a high level of…
AnalizadaMedia (6.4)0.14%—Furbo Mini FirmwareFurbo 360 DOG Camera Firmware12/10/202517/6/2026
A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Root Account Handler. Performing manipulation results in use of hard-coded password. The attack must be initiated from a local position. The attack is considered to have high complexity. The…
AnalizadaBaja (2.9)0.46%—Furbo Mini FirmwareFurbo 360 DOG Camera Firmware12/10/202517/6/2026
A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. Impacted is an unknown function of the file TF_FQDN.json of the component GATT Interface URL Handler. Such manipulation leads to server-side request forgery. The attack may be performed from remote. Attacks of this nature are highly complex. The…