Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

389 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware30/3/202117/6/2026
An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. An unauthenticated attacker can reboot the device causing a Denial of Service, via a hidden reboot command to '/media/?action=cmd'.
ModificadaAlta (8.8)0.51%—Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware30/3/202117/6/2026
Cross Site Request Forgery (CSRF) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B, via all fields to WebUI.
ModificadaMedia (6.7)0.28%—Intel Realsense Depth Camera Manager17/2/202117/6/2026
Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.3)0.50%—Cisco Video Surveillance 8000p IP Camera FirmwareCisco Video Surveillance 8020 IP Camera FirmwareCisco Video Surveillance 8030 IP Camera FirmwareCisco Video Surveillance 8070 IP Camera Firmware+413/1/202117/6/2026
A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. The vulnerability is due to missing checks when Cisco Discovery Protocol messages are processed. An attacker…
ModificadaAlta (8.8)0.75%—Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+48/10/202017/6/2026
A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute arbitrary code on an affected device or cause the device to reload. This vulnerability is due to missing checks when an IP camera processes a…
ModificadaMedia (6.5)0.45%—Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+48/10/202017/6/2026
A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect processing of certain Cisco…
ModificadaAlta (8.8)0.70%—Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+426/8/202017/6/2026
Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabilities are due to missing checks when the IP cameras process…
ModificadaAlta (8.8)0.95%—Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+426/8/202017/6/2026
Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabilities are due to missing checks when the IP cameras process…
ModificadaMedia (6.5)0.57%—Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+426/8/202017/6/2026
A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect processing of certain Cisco…
ModificadaMedia (6.7)0.85%—Netatmo Smart Indoor Camera Firmware23/4/202017/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in firmware versions prior to x.xx of Netatmo Smart Indoor Camera allows an attacker to execute commands on the device. This issue affects: Netatmo Smart Indoor Camera version and prior versions.
ModificadaCrítica (9.8)5.3%💥 ExploitBoschsecurity Nbn-498 Dinion2x Day/night IP Cameras Firmware18/2/202017/6/2026
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.
ModificadaAlta (8.8)5.7%—Cisco Video Surveillance 8400 IP Camera FirmwareCisco Video Surveillance 8030 IP Camera FirmwareCisco Video Surveillance 8020 IP Camera FirmwareCisco Video Surveillance 8000p IP Camera Firmware+45/2/202017/6/2026
A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP Camera. The vulnerability is due to missing checks when processing Cisco Discovery…
ModificadaCrítica (9.8)2.1%—Milesight IP Security Camera Firmware25/10/201917/6/2026
Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations.
ModificadaCrítica (9.8)3.1%—Milesight IP Security Camera Firmware25/10/201917/6/2026
Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource.
ModificadaCrítica (9.8)2.1%—Milesight IP Security Camera Firmware25/10/201917/6/2026
Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the customer has not configured 10 actual user accounts.
ModificadaCrítica (9.8)2.1%—Milesight IP Security Camera Firmware25/10/201917/6/2026
Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.
ModificadaCrítica (9.8)3.2%—Milesight IP Security Camera Firmware25/10/201917/6/2026
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.
ModificadaAlta (7.5)1.9%—Vivotek Camera18/9/201917/6/2026
VIVOTEK IP Camera devices with firmware before 0x20x allow a denial of service via a crafted HTTP header.
ModificadaCrítica (9.8)1.3%—Vivotek Camera10/9/201917/6/2026
An authentication bypass vulnerability in VIVOTEK IPCam versions prior to 0x13a was found.
ModificadaCrítica (9.8)2.6%—Vivotek Camera10/9/201917/6/2026
VIVOTEK IP Camera devices with firmware before 0x20x have a stack-based buffer overflow via a crafted HTTP header.
ModificadaAlta (8.8)1.0%—Xiaoyi YI M1 Mirrorless Camera Firmware6/9/201917/6/2026
An exploitable authentication bypass vulnerability exists in the Bluetooth Low Energy (BLE) authentication module of YI M1 Mirrorless Camera V3.2-cn. An attacker can send a set of BLE commands to trigger this vulnerability, resulting in sensitive data leakage (e.g., personal photos). An attacker can also control the…
ModificadaCrítica (9.8)2.3%—Cylan Clever DOG Smart Camera Panorama Dog-2w FirmwareCylan Clever DOG Smart Camera Plus Dog-2w-v4 Firmware20/6/201917/6/2026
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt.
ModificadaMedia (5.5)0.35%—Cylan Clever DOG Smart Camera Panorama Dog-2w FirmwareCylan Clever DOG Smart Camera Plus Dog-2w-v4 Firmware20/6/201917/6/2026
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the camera allows anyone to view or download the video archive recorded and saved on the external memory…
ModificadaAlta (8.8)2.6%—Ishekar Endoscope Camera Firmware17/6/201917/6/2026
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruption issue and execute remote code on the device. This device acts as an Endoscope camera that allows its users to use it…
ModificadaAlta (8.8)2.6%—Ishekar Endoscope Camera Firmware17/6/201917/6/2026
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruption issue and execute remote code on the device. This device acts as an Endoscope camera that allows its users to use it…