Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.95% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this vulnerability by sending a crafted RTSP… | |
| Aplazada | Crítica (9.8) | 0.95% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AIThttpdAI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by… | |
| Aplazada | Alta (8.6) | 0.43% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by… | |
| Aplazada | Alta (7.5) | 0.55% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing HTTP request body data. A remote attacker may exploit this vulnerability by sending a crafted request with… | |
| Aplazada | Alta (7.5) | 0.73% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of required HTTP request metadata before it is used by the affected components. A… | |
| Aplazada | Alta (7.5) | 0.55% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing filename values in multipart upload data. A remote attacker may exploit this vulnerability by sending a… | |
| Aplazada | Alta (7.5) | 0.35% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of multipart upload headers when processing certificate-related upload fields. A remote attacker may exploit this… | |
| Aplazada | Alta (7.5) | 1.5% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI component. A remote attacker may exploit this… | |
| Aplazada | Crítica (9.1) | 2.7% | — | Geovision Gv-i O BOX 4EAI | 24/6/2026 | 25/6/2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various… | |
| Aplazada | Crítica (9.1) | 2.7% | — | Geovision Gv-i/o BOX 4EAI | 24/6/2026 | 25/6/2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various… | |
| Aplazada | Crítica (9.1) | 2.7% | — | Geovision Gv-i/o BOX 4EAI | 24/6/2026 | 25/6/2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various… | |
| Aplazada | Crítica (10) | 0.60% | — | GV I O BOX 4EAI | 24/6/2026 | 25/6/2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a… | |
| Aplazada | Crítica (10) | 0.60% | — | Geovision Gv-i O BOX 4EAI | 24/6/2026 | 25/6/2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a… | |
| Aplazada | Crítica (10) | 0.60% | — | Geovis Gv-i O BOX 4EAI | 24/6/2026 | 25/6/2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a… | |
| Aplazada | Media (6.2) | 0.34% | — | Geovision Gv-vmsAI | 24/6/2026 | 25/6/2026 | A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted network request can lead to a denial of service. An attacker can impersonate the legitimate server to trigger this vulnerability. | |
| Aplazada | Crítica (9.1) | 2.7% | — | Geovision Gv-i/o BOX 4EAI | 24/6/2026 | 25/6/2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various… | |
| Aplazada | Crítica (10) | 0.60% | 💥 PoC | Geovision Gv-i O BOX 4EAI | 24/6/2026 | 25/6/2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a… | |
| Aplazada | Media (5.3) | 0.58% | — | WP Dsgvo ToolsAI | 19/6/2026 | 22/6/2026 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.39. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to supply an arbitrary victim email… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Gvectors WpforoAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | PHPAIGvectors WpforoAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Gvectors Wpforo ForumAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Gvectors WpforoAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Gvectors Wpforo ForumAI | 1/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6. | |
| Aplazada | Baja (2.1) | 0.45% | — | Pingvin Share Pingvin-shareAI | 26/5/2026 | 23/7/2026 | A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/signIn.tsx of the component Sign-in Auto-Redirect. The manipulation of the argument redirect results in cross site scripting. The attack may be performed from… | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | AmdgvAI | 15/5/2026 | 17/6/2026 | Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via remote code execution. |