Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.2% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary characters in the pureftpd.passwd file during a username change, which in turn allows for bypassing chroot restrictions in the FTP server. An… | |
| Modificada | Alta (8.8) | 4.3% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during NTP server configuration resulting in command injection. An attacker can simply send an HTTP request to the device to… | |
| Modificada | Alta (8.8) | 4.1% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to… | |
| Modificada | Alta (8.8) | 4.1% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to… | |
| Modificada | Alta (8.8) | 4.1% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to… | |
| Modificada | Alta (8.8) | 6.5% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during the SMTP configuration tests resulting in command… | |
| Modificada | Alta (8.8) | 3.5% | — | Foscam C1 Indoor HD Camera Firmware | 29/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger… | |
| Modificada | Alta (8.8) | 3.4% | — | Foscam C1 Indoor HD Camera Firmware | 27/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger… | |
| Modificada | Alta (8.8) | 3.4% | — | Foscam C1 Indoor HD Camera Firmware | 27/6/2017 | 17/6/2026 | In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger… | |
| Modificada | Alta (8.8) | 5.4% | — | Foscam C1 Indoor HD Camera Firmware | 27/6/2017 | 17/6/2026 | An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An… | |
| Modificada | Alta (7.5) | 2.8% | — | Foscam C1 Indoor HD Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the… | |
| Modificada | Alta (7.5) | 2.8% | — | Foscam C1 Indoor HD Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the… | |
| Modificada | Media (6.5) | 2.9% | — | Foscam C1 Indoor HD Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause the application to read a file from disk but a failure to adequately filter characters results in allowing an… | |
| Modificada | Alta (8.8) | 7.9% | — | Foscam C1 Indoor HD Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An… | |
| Modificada | Alta (8.8) | 7.9% | — | Foscam C1 Indoor HD Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An… | |
| Modificada | Crítica (9.8) | 26% | — | Foscam C1 HD Indoor Camera Firmware | 21/6/2017 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the stack frame. An attacker can simply send an http request to the… | |
| Modificada | Alta (8.8) | 18% | 💥 Exploit | Axis Network Camera Firmware | 2/5/2017 | 17/6/2026 | The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml. | |
| Modificada | Alta (8.8) | 0.81% | — | 360fly 4K Camera Firmware | 1/5/2017 | 17/6/2026 | 360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password. This affects firmware 2.1.4. Exploitation can use the 360fly Android or iOS application, or the BlueZ… | |
| Modificada | Media (6.1) | 51% | 💥 Exploit | Axis Network Camera Firmware | 17/4/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. | |
| Modificada | Alta (8.8) | 2.6% | — | Dahuasecurity IP Camera Firmware | 30/3/2017 | 17/6/2026 | Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During exploitation, the first JSON object… | |
| Modificada | Alta (8.8) | 0.48% | — | Keekoonvision Kk002 IP Camera Firmware | 13/3/2017 | 17/6/2026 | Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entire set of other pages). | |
| Modificada | Alta (8.1) | 60% | — | Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware | 27/2/2017 | 17/6/2026 | The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding… | |
| Modificada | Crítica (9.8) | 13% | — | Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware | 27/2/2017 | 17/6/2026 | An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19. When SmartPSS Software is launched, while on the login screen, the software in the background automatically logs in as admin. This… | |
| Modificada | Media (5.9) | 8.9% | — | Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware | 27/2/2017 | 17/6/2026 | Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web Page, Mobile Application, and Desktop Application interfaces, which allows remote attackers to… | |
| Modificada | Alta (8.1) | 4.1% | — | Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware | 4/1/2017 | 17/6/2026 | NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain… |