Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.49% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker. | |
| Modificada | Media (6.5) | 0.42% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password. | |
| Modificada | Media (6.5) | 0.40% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | A buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same network to perform a denial-of-service attack against the device. | |
| Modificada | Media (4.6) | 0.09% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages. | |
| Modificada | Media (6.8) | 0.24% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device. | |
| Modificada | Alta (7.8) | 0.17% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | A vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT credentials that could result in unauthorized access to backend Hubble services. | |
| Modificada | Alta (8.8) | 60% | 💥 Exploit | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device. | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Video Surveillance 7000 IP Camera Firmware | 18/8/2021 | 17/6/2026 | A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for the Cisco Video Surveillance 7000 Series IP Cameras firmware could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper management of memory resources, referred to… | |
| Modificada | Media (6.1) | 0.75% | — | Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware | 30/3/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in the FTP settings page to the "goform/formSetFtpCfg" settings page. | |
| Modificada | Media (6.2) | 0.45% | — | Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware | 30/3/2021 | 17/6/2026 | An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via editing the 'recdata.db' file to call a specially crafted GoAhead ASP-file on the SD card. | |
| Modificada | Alta (8.8) | 1.3% | — | Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware | 30/3/2021 | 17/6/2026 | An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. Authenticated attackers with the "Operator" Privilege can gain admin privileges via a crafted request to '/goform/formUserMng'. | |
| Modificada | Alta (7.5) | 1.3% | — | Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware | 30/3/2021 | 17/6/2026 | An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. An unauthenticated attacker can reboot the device causing a Denial of Service, via a hidden reboot command to '/media/?action=cmd'. | |
| Modificada | Alta (8.8) | 0.51% | — | Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware | 30/3/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B, via all fields to WebUI. | |
| Modificada | Media (4.3) | 0.50% | — | Cisco Video Surveillance 8000p IP Camera FirmwareCisco Video Surveillance 8020 IP Camera FirmwareCisco Video Surveillance 8030 IP Camera FirmwareCisco Video Surveillance 8070 IP Camera Firmware+4 | 13/1/2021 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. The vulnerability is due to missing checks when Cisco Discovery Protocol messages are processed. An attacker… | |
| Modificada | Alta (8.8) | 0.75% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 8/10/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute arbitrary code on an affected device or cause the device to reload. This vulnerability is due to missing checks when an IP camera processes a… | |
| Modificada | Media (6.5) | 0.45% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 8/10/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect processing of certain Cisco… | |
| Modificada | Alta (8.8) | 0.70% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 26/8/2020 | 17/6/2026 | Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabilities are due to missing checks when the IP cameras process… | |
| Modificada | Alta (8.8) | 0.95% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 26/8/2020 | 17/6/2026 | Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabilities are due to missing checks when the IP cameras process… | |
| Modificada | Media (6.5) | 0.57% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 26/8/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect processing of certain Cisco… | |
| Modificada | Media (6.7) | 0.85% | — | Netatmo Smart Indoor Camera Firmware | 23/4/2020 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in firmware versions prior to x.xx of Netatmo Smart Indoor Camera allows an attacker to execute commands on the device. This issue affects: Netatmo Smart Indoor Camera version and prior versions. | |
| Modificada | Alta (8.8) | 5.7% | — | Cisco Video Surveillance 8400 IP Camera FirmwareCisco Video Surveillance 8030 IP Camera FirmwareCisco Video Surveillance 8020 IP Camera FirmwareCisco Video Surveillance 8000p IP Camera Firmware+4 | 5/2/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP Camera. The vulnerability is due to missing checks when processing Cisco Discovery… | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations. | |
| Modificada | Crítica (9.8) | 3.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource. | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the customer has not configured 10 actual user accounts. | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory. |