Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2015 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.5% | — | Raysoft Video CAM Server | 3/5/2005 | 16/6/2026 | Directory traversal vulnerability in Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to read arbitrary files via ".." (dot dot) sequences in an HTTP request. | |
| Modificada | Media (5) | 1.3% | — | Raysoft Video CAM Server | 3/5/2005 | 16/6/2026 | Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space). | |
| Modificada | Alta (7.5) | 1.5% | — | Raysoft Raybase Video CAM ServerAI | 3/5/2005 | 16/6/2026 | Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to conduct administrator operations and cause a denial of service (server or camera shutdown) via a direct request to admin.html. | |
| Modificada | Media (5) | 4.2% | — | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+10 | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using… | |
| Modificada | Media (5) | 2.8% | 💥 PoC | DelegateDnrdDON Moore MydnsMaradns+11 | 31/12/2004 | 16/6/2026 | Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by… | |
| Modificada | Alta (10) | 5.4% | — | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+10 | 31/12/2004 | 16/6/2026 | Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system information via (5) setparam.cgi and (6)… | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+10 | 31/12/2004 | 16/6/2026 | Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi. | |
| Modificada | Media (5) | 1.7% | — | Innomedia Videophone | 23/11/2004 | 16/6/2026 | InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but… | |
| Modificada | Media (5) | 1.2% | — | Phpnuke Video Gallery ModuleAI | 26/4/2004 | 16/6/2026 | modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to gain sensitive information via an HTTP request with an invalid (1) catid or (2) clipid parameter, which reveals the full path in an error message. | |
| Modificada | Media (6.4) | 7.7% | 💥 Exploit | Axis 2400 Video ServerAxis 2401 Video Server | 31/12/2003 | 16/6/2026 | AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file. | |
| Modificada | Alta (10) | 5.3% | 💥 Exploit | Seyeon Flexwatch Network Video Server | 30/10/2003 | 16/6/2026 | FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//). | |
| Modificada | Alta (10) | 30% | 💥 Exploit | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+5 | 9/6/2003 | 16/6/2026 | Las capacidades de administración basadas en web de varios productos Axis Network Camera permite que atacantes remotos se salten las restricciones de acceso y modifiquen la configuración mediante una petición HTTP a admin/admin.shtml que contiene '//" (dos barras) al principio. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Polycom Viavideo | 31/12/2002 | 16/6/2026 | The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requests and leaving the connections open. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Polycom Viavideo | 31/12/2002 | 16/6/2026 | Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. | |
| Modificada | Media (5) | 1.2% | — | Progressive Networks Real Video ServerAI | 15/1/1998 | 16/6/2026 | Progressive Networks Real Video server (pnserver) can be crashed remotely. |