Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
389 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.30% | — | LSC Smart Connect Indoor IP CameraAI | 5/11/2024 | 17/6/2026 | The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user… | |
| Aplazada | Alta (8.4) | 0.96% | — | Kerui HD 3MP 1080p Tuya CameraAI | 30/10/2024 | 17/6/2026 | KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either SSID or PASSWORD, in the JSON data contained within the QR… | |
| Aplazada | Media (5.3) | 0.76% | 💥 PoC | Reolink DUO 2 Wifi CameraAI | 22/10/2024 | 17/6/2026 | Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, such as brute-forcing… | |
| Aplazada | Alta (8.7) | 0.49% | — | D3dsecurity IP Camera D8801AI | 4/10/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-Time Streaming Protocol (RTSP) version for live video streaming. A remote attacker could exploit this vulnerability by crafting a RTSP packet leading to unauthorized access to live feed of the… | |
| Aplazada | Alta (8.7) | 0.36% | — | D3dsecurity IP Camera D8801AI | 4/10/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentication scheme of the HTTP header protocol where authorization tag contain a Base-64 encoded username and password. A remote attacker could exploit this vulnerability by crafting a HTTP packet leading… | |
| Aplazada | Media (6.5) | 0.23% | — | Runofast Indoor Security Camera FOR Baby MonitorAI | 18/9/2024 | 17/6/2026 | runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows access to the /stream1 URI via the rtsp:// protocol to receive the video and audio stream. | |
| Aplazada | Crítica (9.8) | 0.81% | — | Recantha PI CameraAI | 3/9/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The issue arises from improper sanitization of user input passed to the "position" GET parameter in the tilt.php script. An attacker can exploit this by sending crafted input data that includes malicious… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Ezviz Internet PT Camera Cs-cv246AI | 23/8/2024 | 5/7/2026 | Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish RTSP protocol… | |
| Aplazada | Alta (7.1) | 0.69% | — | Victor Zsviot CameraAI | 19/5/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Victor Zsviot Camera 8.26.31. This affects an unknown part of the component MQTT Packet Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Alta (8.8) | 0.71% | — | Wyze CAM V3 FirmwareRoku Indoor Camera SE FirmwareOwletcare CAM FirmwareOwletcare CAM 2 Firmware+1 | 15/5/2024 | 17/6/2026 | ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity | |
| Analizada | Media (6.5) | 0.33% | — | Wyze CAM V3 FirmwareRoku Indoor Camera SE FirmwareOwletcare CAM FirmwareOwletcare CAM 2 Firmware+1 | 15/5/2024 | 17/6/2026 | ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server. | |
| Analizada | Alta (8.8) | 1.0% | — | Wyze CAM V3 FirmwareRoku Indoor Camera SE FirmwareThroughtek Kalay Platform | 15/5/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A specially crafted message can lead to stack-based buffer overflow. An attacker can make authenticated requests to trigger this vulnerability. | |
| Aplazada | Alta (8.2) | 0.38% | — | Section CameraAI | 6/5/2024 | 17/6/2026 | Section Camera V2.5.5.3116-S50-SMA-B20160811 and earlier versions allow the accounts and passwords of administrators and users to be changed without authorization. | |
| Aplazada | Baja (3.3) | 0.21% | — | Tuya Smart Camera U6NAI | 29/4/2024 | 17/6/2026 | An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to the network connection component. | |
| Aplazada | Media (6.5) | 0.22% | — | Secustation CameraAI | 19/4/2024 | 17/6/2026 | SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a crafted request. | |
| Aplazada | Media (5.4) | 0.46% | — | CP Plus Wi-fi CameraAI | 8/4/2024 | 17/6/2026 | A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability is an unknown functionality of the component User Management. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Baja (3.3) | 0.14% | — | Samsung Camera | 2/4/2024 | 17/6/2026 | Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data. | |
| Aplazada | Alta (8.4) | 0.51% | 💥 PoC | YI Smart Kami VisionAIAnts360 YicameraAI | 28/3/2024 | 17/6/2026 | The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component. | |
| Aplazada | Media (5.4) | 0.59% | — | Nuuo CameraAI | 27/3/2024 | 17/6/2026 | A vulnerability was found in NUUO Camera up to 20240319 and classified as problematic. This issue affects some unknown processing of the file /deletefile.php. The manipulation of the argument filename leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Crítica (9.8) | 1.1% | — | Vivotek Camera Firmware | 29/2/2024 | 17/6/2026 | An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component. | |
| Modificada | Media (6.8) | 0.48% | — | Blurams Lumi Security Camera A31c Firmware | 2/2/2024 | 17/6/2026 | An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.2% | — | Blurams Lumi Security Camera A31c Firmware | 2/2/2024 | 17/6/2026 | An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code. | |
| Modificada | Media (5.9) | 0.56% | — | Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+10 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks. | |
| Modificada | Alta (7.8) | 0.26% | — | Huddlycameraservices | 1/12/2023 | 17/6/2026 | An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers to manipulate files and escalate privileges via RollingFileAppender.DeleteFile method performed by the log4net library. | |
| Modificada | Alta (7.8) | 0.32% | — | Huddlycameraservice | 1/12/2023 | 17/6/2026 | DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the installation of the service in a directory that grants write privileges to standard users, allows attackers to manipulate files, execute arbitrary code, and escalate privileges. |