Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1654 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.55% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process. | |
| Aplazada | Alta (7.5) | 0.46% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections. | |
| Aplazada | Crítica (9.4) | 0.51% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands. | |
| Aplazada | Media (4.9) | 0.44% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker. | |
| Aplazada | Media (4.9) | 0.44% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker. | |
| Aplazada | Alta (7.2) | 0.54% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update. | |
| Aplazada | Media (4.9) | 0.44% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker. | |
| Aplazada | Media (4.9) | 0.44% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker. | |
| Aplazada | Media (4.9) | 0.44% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations. | |
| Aplazada | Alta (8.8) | 0.65% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root. | |
| Aplazada | Alta (7.2) | 0.70% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root. | |
| Aplazada | Alta (7.2) | 0.70% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied. | |
| Aplazada | Alta (7.2) | 0.70% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root. | |
| Aplazada | Alta (7.2) | 0.70% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root. | |
| Aplazada | Alta (7.2) | 0.54% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted. | |
| Aplazada | Alta (8.8) | 0.42% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR. | |
| Aplazada | Media (6.5) | 0.37% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated. | |
| Aplazada | Media (6.5) | 0.34% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR. | |
| Aplazada | Media (6.5) | 0.41% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service. | |
| Aplazada | Alta (7.1) | 0.09% | — | C6 EAR CameraAIEarvisionAI | 9/9/2026 | 10/9/2026 | The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and… | |
| Aplazada | Media (6.7) | 0.18% | — | Keyence XG VisionterminalAIKeyence Xg-x VisionterminalAI | 3/9/2026 | 15/9/2026 | XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed. | |
| Aplazada | Baja (2.1) | 0.45% | — | Vidiq Vision FOR Youtube ExtensionAI | 31/8/2026 | 1/9/2026 | A security flaw has been discovered in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. The affected element is the function window.addEventListener of the component postMessage Handler. Performing a manipulation of the argument vidiqEvent results in information disclosure. The attack is possible to be carried… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Cozyvision SMS Alert Order NotificationsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | |
| Aplazada | Baja (1.9) | 0.17% | — | Jane-xiaoer Skill-vision-controlAI | 9/8/2026 | 13/8/2026 | A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path traversal. The attack can only be performed from a local environment. The project… |