Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.2)0.85%—Ptzoptics Pt12x-sdi-xx-g2 FirmwarePtzoptics Pt12x-ndi-xx FirmwarePtzoptics Pt12x-usb-xx-g2 FirmwarePtzoptics Pt20x-sdi-xx-g2 Firmware+575/9/202517/6/2026
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.
AnalizadaCrítica (9.3)0.77%—Ptzoptics Pt12x-sdi-xx-g2 FirmwarePtzoptics Pt12x-ndi-xx FirmwarePtzoptics Pt12x-usb-xx-g2 FirmwarePtzoptics Pt20x-sdi-xx-g2 Firmware+475/9/202517/6/2026
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.
ModificadaCrítica (9.8)0.75%—Yitechnology YI CAR Dashcam Firmware24/2/202517/6/2026
Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.
AnalizadaAlta (8.8)0.71%—Wyze CAM V3 FirmwareRoku Indoor Camera SE FirmwareOwletcare CAM FirmwareOwletcare CAM 2 Firmware+115/5/202417/6/2026
ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity
AnalizadaMedia (6.5)0.33%—Wyze CAM V3 FirmwareRoku Indoor Camera SE FirmwareOwletcare CAM FirmwareOwletcare CAM 2 Firmware+115/5/202417/6/2026
ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.
AnalizadaAlta (8.8)2.7%—Owletcare CAM FirmwareOwletcare CAM 2 FirmwareThroughtek Kalay Platform15/5/202417/6/2026
A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.
ModificadaAlta (7.5)1.3%—Peplink Balance 20X FirmwarePeplink Balance 310x FirmwarePeplink MBX FirmwarePeplink EPX Firmware+517/10/202017/6/2026
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
ModificadaCrítica (9.8)6.8%—Goahead Wireless IP Camera Wificam Firmware11/6/201917/6/2026
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI.
ModificadaAlta (7.5)1.5%—UI Aircam Firmware4/6/201917/6/2026
On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer binary. The issue can be triggered via malformed RTSP requests that lead to an invalid memory read. To exploit the vulnerability, an attacker must craft an RTSP request with a large number of…
ModificadaCrítica (9.8)51%—Airlive Bu-3026 FirmwareAirlive Md-3025 FirmwareAirlive Wl-2000cam FirmwareAirlive Poe-200cam V2 Firmware+128/12/201717/6/2026
cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the…
ModificadaCrítica (9.8)1.8%—Marel A320 FirmwareMarel A325 FirmwareMarel A371 FirmwareMarel A520 Master Firmware+1830/6/201717/6/2026
An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow…
ModificadaCrítica (9.8)2.1%—Marel A320 FirmwareMarel A325 FirmwareMarel A371 FirmwareMarel A520 Master Firmware+1830/6/201717/6/2026
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow…
ModificadaCrítica (9.8)2.6%—Foscam C1 Webcam Firmware21/6/201717/6/2026
Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate device.
ModificadaAlta (8.8)1.6%—Iodata Ts-ptcam/poe FirmwareIodata Ts-ptcam FirmwareIodata Ts-wrlc FirmwareIodata Ts-wlc2 Firmware+328/4/201717/6/2026
Buffer overflow in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier…
ModificadaAlta (8.8)1.7%—Iodata Ts-ptcam/poe FirmwareIodata Ts-ptcam FirmwareIodata Ts-wrlc FirmwareIodata Ts-wlc2 Firmware+328/4/201717/6/2026
TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier allows remote…
ModificadaMedia (6.1)1.2%—Iodata Ts-ptcam/poe FirmwareIodata Ts-ptcam FirmwareIodata Ts-wrlc FirmwareIodata Ts-wlc2 Firmware+328/4/201717/6/2026
HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware…
ModificadaMedia (5.3)1.4%—Swann Swnvw-470cam FirmwareSwann Srnvw-470lcd Firmware18/2/201617/6/2026
Swann SRNVW-470LCD devices with firmware through 0114 and SWNVW-470CAM devices with firmware through 1022 allow remote attackers to watch live video by visiting an unspecified URL.