Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
389 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.15% | — | Samsung Camera | 6/9/2023 | 17/6/2026 | Implicit intent hijacking vulnerability in Camera prior to versions 11.0.16.43 in Android 11, 12.1.00.30, 12.0.07.53, 12.1.03.10 in Android 12, and 13.0.01.43, 13.1.00.83 in Android 13 allows local attacker to access specific file. | |
| Modificada | Crítica (9.8) | 0.63% | — | A2technology Camera Trap Tracking System | 8/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tracking System allows SQL Injection. This issue affects Camera Trap Tracking System: before 3.1905. | |
| Modificada | Crítica (9.8) | 0.60% | — | Milesight Ncr/camera Firmware | 12/6/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method. | |
| Modificada | Alta (8.8) | 1.00% | — | Furbo DOG Camera Firmware | 2/6/2023 | 17/6/2026 | Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated remote attacker in the Bluetooth network with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands or disrupt service. | |
| Modificada | Crítica (9.8) | 4.2% | — | Uniview Camera Firmware | 31/5/2023 | 17/6/2026 | Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve code execution. By using this buffer… | |
| Modificada | Crítica (9.8) | 1.8% | — | Flir Dvtel Camera Firmware | 15/5/2023 | 17/6/2026 | An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device. | |
| Modificada | Crítica (9.8) | 1.9% | — | Agasio Camera Project Agasio Camera Firmware | 15/5/2023 | 17/6/2026 | An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters. | |
| Modificada | Alta (7.5) | 0.57% | — | Milesight Ncr/camera Firmware | 8/5/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request. | |
| Modificada | Alta (7.5) | 0.50% | — | Milesight Ncr/camera Firmware | 8/5/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request. | |
| Modificada | Media (6.1) | 0.41% | — | Pixedelic Camera Slideshow | 20/3/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Manuel Masia | Pixedelic.Com Camera slideshow plugin <= 1.4.0.1 versions. | |
| Modificada | Alta (7.8) | 0.20% | — | Elecom Camera AssistantElecom Quickfiledealer | 15/2/2023 | 17/6/2026 | Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.5) | 0.59% | — | Biltema Baby Camera FirmwareBiltema IP Camera Firmware | 3/2/2023 | 17/6/2026 | Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive information. | |
| Modificada | Crítica (9.8) | 1.1% | — | Festo BUS Module Cpx-e-ep FirmwareFesto BUS Node Cpx-fb32 FirmwareFesto BUS Node Cpx-fb33 FirmwareFesto BUS Node Cpx-fb36 Firmware+95 | 1/12/2022 | 17/6/2026 | In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability. | |
| Modificada | Baja (3.3) | 0.16% | — | Samsung Factorycamera | 7/10/2022 | 17/6/2026 | Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege. | |
| Modificada | Alta (7.8) | 0.23% | — | Samsung Factorycamera | 7/10/2022 | 17/6/2026 | Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamera privilege. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Factorycamerafb | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege. | |
| Modificada | Alta (8.8) | 1.1% | — | Mipcm Mipc Camera Firmware | 26/9/2022 | 17/6/2026 | Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2003161406. | |
| Modificada | Alta (8.8) | 2.5% | — | Mipcm Mipc Camera Firmware | 26/9/2022 | 17/6/2026 | Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remote code execution on cameras running the firmware when a victim logs into a specially crafted mobile app. | |
| Modificada | Baja (3.3) | 0.19% | — | Samsung Cameralyzer | 5/8/2022 | 17/6/2026 | Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege. | |
| Modificada | Media (6.5) | 0.71% | — | Cellinx NVT - IP PTZ Camera Firmware | 18/7/2022 | 17/6/2026 | Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS as root user. | |
| Modificada | Alta (8.8) | 0.54% | — | Cellinx NVT - IP PTZ Camera Firmware | 18/7/2022 | 17/6/2026 | On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera. | |
| Modificada | Media (5.3) | 0.74% | — | Samsung Camera | 12/7/2022 | 17/6/2026 | Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information. | |
| Modificada | Alta (7.5) | 3.7% | 💥 PoC | Netwavepr Indoor IP Camera FirmwareNetwavepr Outdoor IP Camera Firmware | 10/6/2022 | 17/6/2026 | There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password). | |
| Modificada | Alta (7.8) | 0.24% | — | Samsung Factorycamera | 11/4/2022 | 17/6/2026 | Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege. | |
| Modificada | Media (5.5) | 0.59% | — | Samsung Camera | 11/2/2022 | 17/6/2026 | Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status. |