Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
117 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.3% | — | Cisco Video Surveillance Operations Manager | 30/9/2013 | 16/6/2026 | The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attackers to watch video feeds via a crafted URL, aka Bug ID CSCtg72262. | |
| Modificada | Media (5) | 1.5% | — | Cisco Vc240 Network Bullet CameraCisco Video Surveillance Vc220 Network Dome Camera | 1/8/2013 | 16/6/2026 | The Cisco VC220 and VC240 cameras allow remote attackers to cause a denial of service (WebUI outage) via crafted packets, aka Bug IDs CSCtf73188, CSCtf88059, CSCtf87951, CSCtf87908, and CSCtf88019. | |
| Modificada | Alta (7.8) | 9.3% | 💥 Exploit | Cisco Video Surveillance Manager | 25/7/2013 | 16/6/2026 | Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID… | |
| Modificada | Alta (9) | 8.3% | 💥 Exploit | Cisco Video Surveillance Manager | 25/7/2013 | 16/6/2026 | Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288. | |
| Modificada | Alta (7.8) | 10% | 💥 Exploit | Cisco Video Surveillance Manager | 25/7/2013 | 16/6/2026 | Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a crafted URL, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37163. | |
| Modificada | Media (4.3) | 0.96% | — | Cisco Video Surveillance Operations Manager | 14/6/2013 | 16/6/2026 | Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490. | |
| Modificada | Media (6.5) | 7.0% | 💥 Exploit | Qnap Viostor Network Video RecorderQnap Surveillance Station PROQnap NAS | 7/6/2013 | 16/6/2026 | cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string. | |
| Modificada | Media (5) | 1.3% | — | Qnap Viostor Network Video RecorderQnap Surveillance Station PROQnap NAS | 7/6/2013 | 16/6/2026 | QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.2% | — | Cisco Video Surveillance 2421Cisco Video Surveillance 2500Cisco Video Surveillance SoftwareCisco Video Surveillance 2600 | 27/10/2011 | 16/6/2026 | Cisco Video Surveillance 2421 and 2500 series cameras with software 1.1.x and 2.x before 2.4.0 and Video Surveillance 2600 series cameras with software before 4.2.0-13 allow remote attackers to cause a denial of service (device reload) by sending crafted RTSP packets over TCP, aka Bug IDs CSCtj96312, CSCtj39462, and… | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Geovision Digital Surveillance System | 12/9/2011 | 16/6/2026 | Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request. | |
| Modificada | Media (6.8) | 1.1% | — | Cisco Video Surveillance 2500 Series IP Camera | 25/6/2009 | 16/6/2026 | The embedded web server on the Cisco Video Surveillance 2500 Series IP Camera with firmware before 2.1 allows remote attackers to read arbitrary files via a (1) http or (2) https request, related to the (a) SD Camera Web Server and the (b) Wireless Camera HTTP Server, aka Bug IDs CSCsu05515 and CSCsr96497. | |
| Modificada | Alta (7.8) | 1.6% | — | Cisco Video Surveillance Stream Manager | 25/6/2009 | 16/6/2026 | The Cisco Video Surveillance Stream Manager firmware before 5.3, as used on Cisco Video Surveillance Services Platforms and Video Surveillance Integrated Services Platforms, allows remote attackers to cause a denial of service (reboot) via a malformed payload in a UDP packet to port 37000, related to the xvcrman… | |
| Modificada | Media (6.8) | 8.0% | 💥 Exploit | Toshiba Surveillix | 23/1/2008 | 16/6/2026 | Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods. | |
| Modificada | Alta (10) | 3.0% | — | Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP | 6/9/2007 | 16/6/2026 | The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier does not require authentication, which allows remote… | |
| Modificada | Alta (9) | 2.1% | — | Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP | 6/9/2007 | 16/6/2026 | The Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier have default passwords for the sypixx and root user accounts, which allows… | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Geovision Digital Surveillance System | 14/5/2005 | 16/6/2026 | GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image. | |
| Modificada | Alta (7.5) | 1.1% | — | Geovision Digital Surveillance System | 14/5/2005 | 16/6/2026 | GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0 uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via sniffing. |