Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

117 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.6%—Netgear Readynas Surveillance28/4/202017/6/2026
Certain NETGEAR devices are affected by anonymous root access. This affects ReadyNAS Surveillance 1.1.1-3-armel and earlier and ReadyNAS Surveillance 1.4.1-3-amd64 and earlier.
ModificadaAlta (8.8)5.7%—Cisco Video Surveillance 8400 IP Camera FirmwareCisco Video Surveillance 8030 IP Camera FirmwareCisco Video Surveillance 8020 IP Camera FirmwareCisco Video Surveillance 8000p IP Camera Firmware+45/2/202017/6/2026
A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP Camera. The vulnerability is due to missing checks when processing Cisco Discovery…
ModificadaAlta (7.5)1.7%—AUO Sunveillance Monitoring System & Data Recorder12/11/201917/6/2026
AUO SunVeillance Monitoring System before v1.1.9e is vulnerable to mvc_send_mail.aspx (MailAdd parameter) SQL Injection. An Attacker can carry a SQL Injection payload to the server, allowing the attacker to read privileged data. This also affects the picture_manage_mvc.aspx plant_no parameter, the swapdl_mvc.aspx…
ModificadaCrítica (9.8)2.1%—AUO Sunveillance Monitoring System & Data Recorder12/11/201917/6/2026
An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnerability that can allow an unauthenticated user to upload files via a modified authority parameter.
ModificadaAlta (7.1)1.0%—Siemens Siveillance Video Management Software 2017 R2Siemens Siveillance Video Management Software 2018 R1Siemens Siveillance Video Management Software 2018 R2Siemens Siveillance Video Management Software 2018 R3+112/6/201917/6/2026
A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions < V13.1a). An attacker with network access to…
ModificadaAlta (8.8)1.3%—Siemens Siveillance Video Management Software 2017 R2Siemens Siveillance Video Management Software 2018 R1Siemens Siveillance Video Management Software 2018 R2Siemens Siveillance Video Management Software 2018 R3+112/6/201917/6/2026
A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions < V13.1a). An attacker with network access to…
ModificadaCrítica (9.8)1.7%—Siemens Siveillance Video Management Software 2017 R2Siemens Siveillance Video Management Software 2018 R1Siemens Siveillance Video Management Software 2018 R2Siemens Siveillance Video Management Software 2018 R3+112/6/201917/6/2026
A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions < V13.1a). An attacker with network access to…
ModificadaCrítica (9.8)8.2%—Netgear Readynas Surveillance Firmware11/6/201917/6/2026
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.
ModificadaAlta (7.5)10%—Cisco Video Surveillance Manager15/5/201917/6/2026
A vulnerability in the web-based management interface of Cisco Video Surveillance Manager could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability is due to improper validation of parameters handled by the web-based management interface. An attacker could exploit this…
ModificadaMedia (6.5)1.7%—Cisco Video Surveillance Media Server8/11/201817/6/2026
A vulnerability in the web-based management interface of Cisco Video Surveillance Media Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by…
ModificadaCrítica (9.8)6.8%—Cisco Video Surveillance Manager5/10/201817/6/2026
A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the root account, which has default, static user credentials. The…
ModificadaAlta (7.5)98%💥 ExploitArgussurveillance DVR30/8/201817/6/2026
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.
ModificadaAlta (7.4)0.72%—Siemens Siveillance VMS Video3/5/201817/6/2026
A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (2018 R1)), Siveillance VMS Video for iOS (All versions < V12.1a (2018 R1)). Improper certificate validation could allow an attacker in a privileged network position to read data from and write data to the encrypted…
ModificadaAlta (8.1)4.0%—Milestonesys XprotectSiemens Siveillance VMS30/4/201817/6/2026
The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.a) to 2018 R1 (12.1a) contains .NET Remoting endpoints that are vulnerable to deserialization attacks resulting in remote code execution.
ModificadaMedia (6.5)1.8%—Synology Surveillance Station27/2/201817/6/2026
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the filename parameter.
ModificadaMedia (5.4)1.0%—Synology Surveillance Station27/2/201817/6/2026
Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inject arbitrary web script or HTML via the userDesc parameter.
ModificadaAlta (8.8)17%💥 ExploitNuuo Nvrmini 2Netgear Readynas Surveillance31/8/201617/6/2026
Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary code via the sn parameter to the transfer_license command.
ModificadaAlta (8.8)14%💥 ExploitNuuo Nvrmini 2Netgear Readynas Surveillance31/8/201617/6/2026
cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transfer_license command.
ModificadaAlta (7.5)12%💥 ExploitNetgear Readynas SurveillanceNuuo Nvrmini 2Nuuo Nvrsolo31/8/201617/6/2026
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request.
ModificadaAlta (7.5)54%💥 ExploitNetgear Readynas SurveillanceNuuo NvrsoloNuuo Nvrmini 231/8/201617/6/2026
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action.
ModificadaCrítica (9.8)71%💥 ExploitNetgear Readynas SurveillanceNuuo CrystalNuuo NvrsoloNuuo Nvrmini 231/8/201617/6/2026
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
ModificadaCrítica (9.8)95%💥 ExploitNetgear Readynas SurveillanceNuuo Nvrmini 2Nuuo Nvrsolo31/8/201617/6/2026
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.
ModificadaMedia (4.3)2.2%—Cisco Video Surveillance Indoor Fixed Dome IP HD Camera25/1/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCud10943 and CSCud10950.
ModificadaMedia (6.8)1.6%—Cisco Video Surveillance Operations Manager24/1/201417/6/2026
Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from a client system with a crafted host name, aka Bug ID…
ModificadaMedia (6.4)1.2%—Cisco Video Surveillance 4000 IP CameraCisco Video Surveillance 4300e IP CameraCisco Video Surveillance 4500e IP Camera16/10/201316/6/2026
The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419.
Orbitaley — Vulnerabilidades