Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.2% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password. | |
| Modificada | Alta (8.8) | 1.0% | — | Xiaoyi YI M1 Mirrorless Camera Firmware | 6/9/2019 | 17/6/2026 | An exploitable authentication bypass vulnerability exists in the Bluetooth Low Energy (BLE) authentication module of YI M1 Mirrorless Camera V3.2-cn. An attacker can send a set of BLE commands to trigger this vulnerability, resulting in sensitive data leakage (e.g., personal photos). An attacker can also control the… | |
| Modificada | Alta (8.8) | 2.6% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruption issue and execute remote code on the device. This device acts as an Endoscope camera that allows its users to use it… | |
| Modificada | Alta (8.8) | 2.6% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruption issue and execute remote code on the device. This device acts as an Endoscope camera that allows its users to use it… | |
| Modificada | Alta (7.8) | 0.73% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi password. This application is installed on the device… | |
| Modificada | Media (6.5) | 1.6% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car garages, and also in… | |
| Modificada | Alta (7.8) | 0.73% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi name. This application is installed on the device and an… | |
| Modificada | Media (6.5) | 2.1% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has default Wi-Fi credentials that are exactly the same for every device. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and… | |
| Modificada | Media (6.5) | 1.9% | — | Ishekar Endoscope Camera Firmware | 17/6/2019 | 17/6/2026 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that any malicious user connecting to the device can change the default SSID and password thereby denying the owner an access to his/her own device. This device acts as an Endoscope camera that allows… | |
| Modificada | Crítica (9.8) | 1.4% | — | Guardzilla 360 Outdoor FirmwareGuardzilla 180 Outdoor FirmwareGuardzilla 360 Indoor FirmwareGuardzilla 180 Indoor Firmware+2 | 31/12/2018 | 17/6/2026 | The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring. | |
| Modificada | Crítica (9.8) | 1.9% | — | Bosch 360-indoor Camera FirmwareBosch Eyes Outdoor Camera Firmware | 19/12/2018 | 17/6/2026 | An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there is a buffer overflow in the RCP+ parser… | |
| Modificada | Alta (7.5) | 1.4% | — | Qacctv Jooan Ja-q1h Wi-fi Camera Firmware | 10/12/2018 | 17/6/2026 | Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via certain ONVIF methods such as CreateUsers, SetImagingSettings, GetStreamUri, and so on. | |
| Modificada | Alta (7.5) | 1.5% | — | Qacctv Jooan Ja-q1h Wi-fi Camera Firmware | 10/12/2018 | 17/6/2026 | Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via the ONVIF GetStreamUri method and GetVideoEncoderConfigurationOptions method. | |
| Modificada | Alta (7.5) | 2.3% | — | Yitechnology YI Home Camera FirmwareYitechnology YI Home | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can allocate unlimited memory, resulting in denial of service. An attacker can send a set of packets to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 2.6% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a logic flaw, resulting in an authentication bypass. An attacker can sniff network traffic and send a set of packets to trigger this vulnerability. | |
| Modificada | Media (6.8) | 0.59% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7.0D. A specially crafted 7-Zip file can cause a CRC collision, resulting in a firmware update and code execution. An attacker can insert an SDcard to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.9% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return… | |
| Modificada | Alta (7.5) | 1.9% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return… | |
| Modificada | Alta (8.1) | 2.7% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted packet can cause a buffer overflow, resulting in code execution. An attacker can intercept and alter network traffic to trigger this vulnerability. | |
| Modificada | Media (4.6) | 0.40% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw, resulting in a firmware downgrade. An attacker can insert an SD card to trigger this vulnerability. | |
| Modificada | Media (6.8) | 1.7% | — | Yitechnology YI Home Camera Firmware | 2/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw and command injection, resulting in code execution. An attacker can insert an SD card to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 1.3% | — | Yitechnology YI Home Camera FirmwareYitechnology YI Home | 1/11/2018 | 17/6/2026 | An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US 1.8.7.0D. An attacker can sniff network traffic to exploit this vulnerability. | |
| Modificada | Alta (7.5) | 2.3% | — | Yitechnology YI Home Camera Firmware | 1/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a settings change, resulting in denial of service. An attacker can send a set of packets to trigger this vulnerability. | |
| Modificada | Alta (8) | 1.6% | — | Yitechnology YI Home Camera FirmwareYitechnology YI Home | 1/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker can cause a camera to connect to this SSID to trigger this vulnerability. Alternatively, an attacker… | |
| Modificada | Alta (8.8) | 2.6% | — | Yitechnology YI Home Camera FirmwareYitechnology YI Home | 1/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. An attacker can make the camera scan a QR code to trigger this vulnerability. Alternatively, a user could be… |