Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

389 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.4)0.18%—Fortinet Forticamera FirmwareFortinet FortimailFortinet FortindrFortinet Fortirecorder+112/8/202517/6/2026
Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions,…
AnalizadaMedia (5.1)0.17%—Axis Camera StationAxis Camera Station PRO12/8/202517/6/2026
During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal resources on the server was discovered.
ModificadaAlta (7.8)0.15%—Aziot 2MP Full HD Smart Wi-fi Cctv Home Security Camera Firmware30/7/20255/7/2026
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in…
AnalizadaMedia (5.3)0.65%—Axis Camera StationAxis Camera Station PRO11/7/202517/6/2026
The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
AnalizadaMedia (4.8)0.18%—Axis Camera Station PROAxis Device Manager11/7/202517/6/2026
The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
AnalizadaCrítica (9)0.62%—Axis Camera StationAxis Camera Station PROAxis Device Manager11/7/202517/6/2026
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
AplazadaAlta (8.3)0.32%—Avtech IP CamerasAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.
AplazadaMedia (6.9)0.62%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.
AplazadaCrítica (9.4)1.8%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are directly embedded into system commands without proper sanitation.…
AplazadaCrítica (9.4)1.5%—Avtech DVRAIAvtech NVRAIAvtech IP CameraAI1/7/202517/6/2026
An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke the DoShellCmd operation, passing arbitrary input via the strCmd parameter. This input is executed directly by the system…
AplazadaMedia (6.9)0.63%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.
AplazadaMedia (5.1)0.28%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user…
AplazadaMedia (5.1)0.14%—I-pro Surveillance CameraAI6/6/202517/6/2026
Cross-site request forgery vulnerability exists in surveillance cameras provided by i-PRO Co., Ltd.. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
AnalizadaCrítica (9.8)30%⚠ Explotación activaFortinet FortimailFortinet FortindrFortinet FortirecorderFortinet Fortivoice+113/5/202517/6/2026
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0,…
AplazadaMedia (6.8)0.17%—I-pro Configuration ToolAII-pro Surveillance CamerasAII-pro RecordersAI24/4/202517/6/2026
Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameras and recorders.
AnalizadaMedia (6.5)0.24%—Axis Camera Station PRO23/4/202517/6/2026
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admin-protected location. Axis has released a patched version for the highlighted…
AnalizadaAlta (7.3)0.23%—Axis Camera Station PRO23/4/202517/6/2026
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a boot loop by redirecting a file deletion when recording video. Axis has released a patched version for the highlighted flaw. Please refer to the Axis security advisory…
AnalizadaAlta (7.7)0.58%—LSC PTZ Dual Band Camera Firmware11/3/202517/6/2026
LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.
AplazadaMedia (6.9)51%—Nuuo CameraAI16/2/202517/6/2026
A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function print_file of the file /handle_config.php. The manipulation of the argument log leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the…
AplazadaMedia (6.1)0.23%—Secustation CameraAI27/1/202517/6/2026
SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower is vulnerable to Cross Site Scripting (XSS).
AnalizadaMedia (6.3)0.23%—Axis Camera Station PRO7/1/202517/6/2026
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with audit log creation in AXIS Camera Station, or perform a Denial-of-Service attack on the AXIS Camera Station server using maliciously crafted audit log entries. Axis has…
AplazadaMedia (4.4)0.16%—Axis Camera Station PROAI26/11/202417/6/2026
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check. Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and…
AplazadaMedia (6.3)0.14%—Axis Camera StationAI26/11/202417/6/2026
Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If Incident report is not being used with credentials configured this flaw does not apply. Axis has released patched versions for…
AplazadaMedia (4.2)0.12%—Axis Camera Station PROAI26/11/202417/6/2026
Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart. Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more…
AplazadaAlta (8.2)0.25%—TCL CameraAI14/11/202417/6/2026
The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path and delete arbitrary files from user’s external storage.