Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
84 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.6% | — | Dahuasecurity IP Camera Firmware | 30/3/2017 | 17/6/2026 | Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During exploitation, the first JSON object… | |
| Modificada | Alta (8.8) | 0.48% | — | Keekoonvision Kk002 IP Camera Firmware | 13/3/2017 | 17/6/2026 | Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entire set of other pages). | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Foscam IP Camera Firmware | 14/5/2014 | 17/6/2026 | Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifying arbitrary camera records in the Foscam DNS server. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Maygion IP Camera Firmware | 25/3/2014 | 16/6/2026 | Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in a GET request. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Maygion IP Camera Firmware | 25/3/2014 | 16/6/2026 | Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI. | |
| Modificada | Media (4.3) | 1.9% | — | Foscam Wireless IP Camera | 20/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web interface "WiFi scan" option in FOSCAM Wireless IP Cameras allows remote attackers to inject arbitrary web script or HTML via the SSID. | |
| Modificada | Media (6.4) | 1.2% | — | Cisco Video Surveillance 4000 IP CameraCisco Video Surveillance 4300e IP CameraCisco Video Surveillance 4500e IP Camera | 16/10/2013 | 16/6/2026 | The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419. | |
| Modificada | Alta (10) | 3.8% | — | Foscam H.264 Hi3510/11/12 IP CameraWansview H.264 Hi3510/11/12 IP Camera | 21/12/2012 | 16/6/2026 | The web interface on (1) Foscam and (2) Wansview IP cameras allows remote attackers to bypass authentication, and perform administrative functions or read the admin password, via a direct request to an unspecified URL. | |
| Modificada | Media (6.8) | 1.1% | — | Cisco Video Surveillance 2500 Series IP Camera | 25/6/2009 | 16/6/2026 | The embedded web server on the Cisco Video Surveillance 2500 Series IP Camera with firmware before 2.1 allows remote attackers to read arbitrary files via a (1) http or (2) https request, related to the (a) SD Camera Web Server and the (b) Wireless Camera HTTP Server, aka Bug IDs CSCsu05515 and CSCsr96497. |