Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 12% | 💥 Exploit | Hikvision Ds-2cd7153-e Firmware | 27/12/2019 | 16/6/2026 | Hikvision DS-2CD7153-E IP Camera has Privilege Escalation | |
| Modificada | Crítica (9.8) | 2.3% | — | Hikvision IP Cameras | 13/8/2018 | 17/6/2026 | A buffer overflow vulnerability in the web server of some Hikvision IP Cameras allows an attacker to send a specially crafted message to affected devices. Due to the insufficient input validation, successful exploit can corrupt memory and lead to arbitrary code execution or crash the process. | |
| Modificada | Alta (7.5) | 1.7% | — | Hikvision Ds-2cd9111-s Firmware | 18/4/2018 | 17/6/2026 | There is a buffer overflow in the Hikvision Camera DS-2CD9111-S of V4.1.2 build 160203 and before, and this vulnerability allows remote attackers to launch a denial of service attack (service interruption) via a crafted network setting interface request. | |
| Modificada | Media (6.5) | 0.49% | — | Hikvision Ds-2cd2432f-iw Firmware | 1/12/2017 | 17/6/2026 | HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger association with an arbitrary access point by leveraging a default SSID with no WiFi encryption or authentication. NOTE: Vendor states that this is not a vulnerability, but more an increase to the attack… | |
| Modificada | Alta (7.8) | 0.46% | — | Hikvision Ivms-4200 | 30/8/2017 | 17/6/2026 | Hikvision iVMS-4200 devices before v2.6.2.7 allow local users to generate password-recovery codes via unspecified vectors. | |
| Modificada | Alta (8.8) | 2.4% | — | Hikvision Ds-2cd2032-i FirmwareHikvision Ds-2cd2112-i FirmwareHikvision Ds-2cd2132-i FirmwareHikvision Ds-2cd2212-i5 Firmware+54 | 6/5/2017 | 17/6/2026 | A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Hikvision Ds-2cd2032-i FirmwareHikvision Ds-2cd2112-i FirmwareHikvision Ds-2cd2132-i FirmwareHikvision Ds-2cd2212-i5 Firmware+54 | 6/5/2017 | 17/6/2026 | An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build… | |
| Modificada | Media (6.5) | 1.3% | — | Hikvision Ds-76xxx Series FirmwareHikvision Ds-77xxx Series Firmware | 13/3/2017 | 17/6/2026 | Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the SDK issue. | |
| Modificada | Media (6.5) | 1.3% | — | Hikvision Ds-76xxx Series FirmwareHikvision Ds-77xxx Series Firmware | 13/3/2017 | 17/6/2026 | Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the ISAPI issue. | |
| Modificada | Media (6.5) | 1.3% | — | Hikvision Ds-76xxx Series FirmwareHikvision Ds-77xxx Series Firmware | 13/3/2017 | 17/6/2026 | Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the PSIA issue. | |
| Modificada | Alta (7.5) | 71% | 💥 Exploit | Hikvision DVR Ds-7204 Firmware | 8/12/2014 | 17/6/2026 | Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote attackers to execute arbitrary code via an RTSP PLAY request with a long Authorization header. | |
| Modificada | Alta (10) | 17% | 💥 Exploit | Hikvision Ds-2cd7153-e FirmwareHikvision Ds-2cd7153-e | 3/3/2014 | 16/6/2026 | Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause a denial of service (device crash and reboot) and possibly execute arbitrary code via a long string in the Range header field in an RTSP… |