Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.78% | — | Dahuasecurity Ipc-hdw1x2x FirmwareDahuasecurity Ipc-hfw1x2x FirmwareDahuasecurity Ipc-hdw2x2x FirmwareDahuasecurity Ipc-hfw2x2x Firmware+5 | 17/9/2019 | 17/6/2026 | Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for… | |
| Modificada | Alta (7.5) | 25% | 💥 Exploit | Amcrest Ip2m-841b FirmwareDahua Dh-ipc-hx863xDahua Dh-ipc-hx883xDahua Dh-sd4xxxxx+8 | 29/7/2019 | 17/6/2026 | The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R,… | |
| Modificada | Alta (7.8) | 0.45% | — | Dahuasecurity Ipc-hfw1xxx FirmwareDahuasecurity Ipc-hdw1xxx FirmwareDahuasecurity Ipc-hfw2xxx Firmware | 12/6/2019 | 17/6/2026 | Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 2018/11. The vulnerability exits in the function of redirection display for serial port printing information, which can not be used by product basic functions. After an attacker logs in locally, this… | |
| Modificada | Crítica (9.8) | 5.2% | — | Dahuasecurity IP Camera Firmware | 24/7/2018 | 17/6/2026 | Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerable to a stack buffer overflow. Dahua IP camera products include an application known as Sonia (/usr/bin/sonia) that provides the web interface and other services for… | |
| Modificada | Alta (8.8) | 0.96% | — | Dahuasecurity Xvr5x16 FirmwareDahuasecurity Xvr5x08 FirmwareDahuasecurity Xvr5x04 FirmwareDahuasecurity Xvr7x16 Firmware+2 | 23/5/2018 | 17/6/2026 | Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device. | |
| Modificada | Crítica (9.8) | 1.4% | — | Dahuasecurity Ipc-hfw1xxx FirmwareDahuasecurity Ipc-hdw1xxx FirmwareDahuasecurity Ipc-hdbw1xxx FirmwareDahuasecurity Ipc-hfw2xxx Firmware+21 | 28/11/2017 | 17/6/2026 | Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism is potentially at risk of being compromised and subsequently utilized by attacker. | |
| Modificada | Media (6.5) | 1.9% | — | Dahuasecurity Nvr11hs FirmwareDahuasecurity Ipc-hdw4300s FirmwareDahuasecurity Ipc-hfw4x00 FirmwareDahuasecurity Ipc-hdw4x00 Firmware+5 | 27/11/2017 | 17/6/2026 | Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal Debug function. This particular function was used for problem analysis and performance tuning during product development phase. It allowed the device to receive only… | |
| Modificada | Alta (8.8) | 0.93% | — | Dahuasecurity Nvr5464-16p-4ks2 FirmwareDahuasecurity Nvr5208-8p-4ks2 FirmwareDahuasecurity Nvr5432-16p-4ks2 FirmwareDahuasecurity Nvr5416-16p-4ks2 Firmware+18 | 13/11/2017 | 17/6/2026 | Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message. | |
| Modificada | Alta (7.3) | 37% | — | Dahuasecurity Dh-ipc-hdbw23a0rn-zs FirmwareDahuasecurity Dh-ipc-hdbw13a0sn FirmwareDahuasecurity Dh-ipc-hdw1xxx FirmwareDahuasecurity Dh-ipc-hdw2xxx Firmware+11 | 6/5/2017 | 17/6/2026 | A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3,… | |
| Modificada | Crítica (9.8) | 51% | 💥 Exploit | Dahuasecurity Dh-ipc-hdbw23a0rn-zs FirmwareDahuasecurity Dh-ipc-hdbw13a0sn FirmwareDahuasecurity Dh-ipc-hdw1xxx FirmwareDahuasecurity Dh-ipc-hdw2xxx Firmware+11 | 6/5/2017 | 17/6/2026 | A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices.… | |
| Modificada | Alta (8.8) | 2.6% | — | Dahuasecurity IP Camera Firmware | 30/3/2017 | 17/6/2026 | Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During exploitation, the first JSON object… | |
| Modificada | Alta (8.1) | 0.91% | — | Dahuasecurity NVR Firmware | 9/3/2017 | 17/6/2026 | An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, is an unencrypted, binary protocol. Performing a Man-in-the-Middle attack allows both sniffing and injections of packets, which allows creation of fully privileged new… | |
| Modificada | Alta (8.1) | 60% | — | Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware | 27/2/2017 | 17/6/2026 | The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding… | |
| Modificada | Crítica (9.8) | 13% | — | Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware | 27/2/2017 | 17/6/2026 | An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19. When SmartPSS Software is launched, while on the login screen, the software in the background automatically logs in as admin. This… | |
| Modificada | Media (5.9) | 8.9% | — | Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware | 27/2/2017 | 17/6/2026 | Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web Page, Mobile Application, and Desktop Application interfaces, which allows remote attackers to… | |
| Modificada | Alta (7.5) | 70% | 💥 Exploit | Dahuasecurity DVR Firmware | 11/7/2014 | 16/6/2026 | Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777. | |
| Modificada | Alta (10) | 3.6% | — | Dahuasecurity Dvr0404hd-aDahuasecurity Dvr0404hd-lDahuasecurity Dvr0404hd-sDahuasecurity Dvr0404hd-u+61 | 17/9/2013 | 16/6/2026 | The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which makes it easier for remote attackers to obtain administrative access and change the administrator password via requests involving (1) ActiveX, (2) a standalone client,… | |
| Modificada | Alta (7.8) | 7.7% | 💥 Exploit | Dahuasecurity Dvr0404hd-aDahuasecurity Dvr0404hd-lDahuasecurity Dvr0404hd-sDahuasecurity Dvr0404hd-u+61 | 17/9/2013 | 16/6/2026 | Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack. | |
| Modificada | Alta (7.8) | 6.7% | 💥 Exploit | Dahuasecurity Dvr0404hd-aDahuasecurity Dvr0404hd-lDahuasecurity Dvr0404hd-sDahuasecurity Dvr0404hd-u+61 | 17/9/2013 | 16/6/2026 | Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port. | |
| Modificada | Alta (9.3) | 7.0% | 💥 Exploit | Dahuasecurity Dvr0404hd-aDahuasecurity Dvr0404hd-lDahuasecurity Dvr0404hd-sDahuasecurity Dvr0404hd-u+61 | 17/9/2013 | 16/6/2026 | Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Dahuasecurity Dvr0404hd-aDahuasecurity Dvr0404hd-lDahuasecurity Dvr0404hd-sDahuasecurity Dvr0404hd-u+61 | 17/9/2013 | 16/6/2026 | Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors. |