Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

159 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.2%—Foscam C1 Indoor HD Camera Firmware29/6/201717/6/2026
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary characters in the pureftpd.passwd file during a username change, which in turn allows for bypassing chroot restrictions in the FTP server. An…
ModificadaAlta (8.8)4.3%—Foscam C1 Indoor HD Camera Firmware29/6/201717/6/2026
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during NTP server configuration resulting in command injection. An attacker can simply send an HTTP request to the device to…
ModificadaAlta (8.8)4.1%—Foscam C1 Indoor HD Camera Firmware29/6/201717/6/2026
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to…
ModificadaAlta (8.8)4.1%—Foscam C1 Indoor HD Camera Firmware29/6/201717/6/2026
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to…
ModificadaAlta (8.8)4.1%—Foscam C1 Indoor HD Camera Firmware29/6/201717/6/2026
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to…
ModificadaAlta (8.8)6.5%—Foscam C1 Indoor HD Camera Firmware29/6/201717/6/2026
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during the SMTP configuration tests resulting in command…
ModificadaAlta (8.8)3.5%—Foscam C1 Indoor HD Camera Firmware29/6/201717/6/2026
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger…
ModificadaAlta (8.8)3.4%—Foscam C1 Indoor HD Camera Firmware27/6/201717/6/2026
In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger…
ModificadaAlta (8.8)3.4%—Foscam C1 Indoor HD Camera Firmware27/6/201717/6/2026
In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger…
ModificadaAlta (8.8)5.4%—Foscam C1 Indoor HD Camera Firmware27/6/201717/6/2026
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An…
ModificadaAlta (7.5)2.8%—Foscam C1 Indoor HD Camera Firmware21/6/201717/6/2026
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the…
ModificadaAlta (7.5)2.8%—Foscam C1 Indoor HD Camera Firmware21/6/201717/6/2026
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the…
ModificadaMedia (6.5)2.9%—Foscam C1 Indoor HD Camera Firmware21/6/201717/6/2026
An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause the application to read a file from disk but a failure to adequately filter characters results in allowing an…
ModificadaAlta (8.8)7.9%—Foscam C1 Indoor HD Camera Firmware21/6/201717/6/2026
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An…
ModificadaAlta (8.8)7.9%—Foscam C1 Indoor HD Camera Firmware21/6/201717/6/2026
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An…
ModificadaCrítica (9.8)26%—Foscam C1 HD Indoor Camera Firmware21/6/201717/6/2026
An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the stack frame. An attacker can simply send an http request to the…
ModificadaAlta (8.8)18%💥 ExploitAxis Network Camera Firmware2/5/201717/6/2026
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.
ModificadaAlta (8.8)0.81%—360fly 4K Camera Firmware1/5/201717/6/2026
360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password. This affects firmware 2.1.4. Exploitation can use the 360fly Android or iOS application, or the BlueZ…
ModificadaMedia (6.1)51%💥 ExploitAxis Network Camera Firmware17/4/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
ModificadaAlta (8.8)2.6%—Dahuasecurity IP Camera Firmware30/3/201717/6/2026
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During exploitation, the first JSON object…
ModificadaAlta (8.8)0.48%—Keekoonvision Kk002 IP Camera Firmware13/3/201717/6/2026
Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entire set of other pages).
ModificadaAlta (8.1)60%—Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware27/2/201717/6/2026
The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding…
ModificadaCrítica (9.8)13%—Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware27/2/201717/6/2026
An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19. When SmartPSS Software is launched, while on the login screen, the software in the background automatically logs in as admin. This…
ModificadaMedia (5.9)8.9%—Dahuasecurity Camera FirmwareDahuasecurity NVR FirmwareDahuasecurity Smartpss Firmware27/2/201717/6/2026
Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web Page, Mobile Application, and Desktop Application interfaces, which allows remote attackers to…
ModificadaAlta (8.1)4.1%—Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware4/1/201717/6/2026
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain…