Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.2) | 0.85% | — | Ptzoptics Pt12x-sdi-xx-g2 FirmwarePtzoptics Pt12x-ndi-xx FirmwarePtzoptics Pt12x-usb-xx-g2 FirmwarePtzoptics Pt20x-sdi-xx-g2 Firmware+57 | 5/9/2025 | 17/6/2026 | PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface. | |
| Analizada | Crítica (9.3) | 0.77% | — | Ptzoptics Pt12x-sdi-xx-g2 FirmwarePtzoptics Pt12x-ndi-xx FirmwarePtzoptics Pt12x-usb-xx-g2 FirmwarePtzoptics Pt20x-sdi-xx-g2 Firmware+47 | 5/9/2025 | 17/6/2026 | PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user. | |
| Modificada | Crítica (9.8) | 0.75% | — | Yitechnology YI CAR Dashcam Firmware | 24/2/2025 | 17/6/2026 | Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset. | |
| Analizada | Alta (8.8) | 0.71% | — | Wyze CAM V3 FirmwareRoku Indoor Camera SE FirmwareOwletcare CAM FirmwareOwletcare CAM 2 Firmware+1 | 15/5/2024 | 17/6/2026 | ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity | |
| Analizada | Media (6.5) | 0.33% | — | Wyze CAM V3 FirmwareRoku Indoor Camera SE FirmwareOwletcare CAM FirmwareOwletcare CAM 2 Firmware+1 | 15/5/2024 | 17/6/2026 | ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server. | |
| Analizada | Alta (8.8) | 2.7% | — | Owletcare CAM FirmwareOwletcare CAM 2 FirmwareThroughtek Kalay Platform | 15/5/2024 | 17/6/2026 | A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Peplink Balance 20X FirmwarePeplink Balance 310x FirmwarePeplink MBX FirmwarePeplink EPX Firmware+51 | 7/10/2020 | 17/6/2026 | Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin. | |
| Modificada | Crítica (9.8) | 6.8% | — | Goahead Wireless IP Camera Wificam Firmware | 11/6/2019 | 17/6/2026 | An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI. | |
| Modificada | Alta (7.5) | 1.5% | — | UI Aircam Firmware | 4/6/2019 | 17/6/2026 | On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer binary. The issue can be triggered via malformed RTSP requests that lead to an invalid memory read. To exploit the vulnerability, an attacker must craft an RTSP request with a large number of… | |
| Modificada | Crítica (9.8) | 51% | — | Airlive Bu-3026 FirmwareAirlive Md-3025 FirmwareAirlive Wl-2000cam FirmwareAirlive Poe-200cam V2 Firmware+1 | 28/12/2017 | 17/6/2026 | cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the… | |
| Modificada | Crítica (9.8) | 1.8% | — | Marel A320 FirmwareMarel A325 FirmwareMarel A371 FirmwareMarel A520 Master Firmware+18 | 30/6/2017 | 17/6/2026 | An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow… | |
| Modificada | Crítica (9.8) | 2.1% | — | Marel A320 FirmwareMarel A325 FirmwareMarel A371 FirmwareMarel A520 Master Firmware+18 | 30/6/2017 | 17/6/2026 | A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow… | |
| Modificada | Crítica (9.8) | 2.6% | — | Foscam C1 Webcam Firmware | 21/6/2017 | 17/6/2026 | Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate device. | |
| Modificada | Alta (8.8) | 1.6% | — | Iodata Ts-ptcam/poe FirmwareIodata Ts-ptcam FirmwareIodata Ts-wrlc FirmwareIodata Ts-wlc2 Firmware+3 | 28/4/2017 | 17/6/2026 | Buffer overflow in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier… | |
| Modificada | Alta (8.8) | 1.7% | — | Iodata Ts-ptcam/poe FirmwareIodata Ts-ptcam FirmwareIodata Ts-wrlc FirmwareIodata Ts-wlc2 Firmware+3 | 28/4/2017 | 17/6/2026 | TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier allows remote… | |
| Modificada | Media (6.1) | 1.2% | — | Iodata Ts-ptcam/poe FirmwareIodata Ts-ptcam FirmwareIodata Ts-wrlc FirmwareIodata Ts-wlc2 Firmware+3 | 28/4/2017 | 17/6/2026 | HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware… | |
| Modificada | Media (5.3) | 1.4% | — | Swann Swnvw-470cam FirmwareSwann Srnvw-470lcd Firmware | 18/2/2016 | 17/6/2026 | Swann SRNVW-470LCD devices with firmware through 0114 and SWNVW-470CAM devices with firmware through 1022 allow remote attackers to watch live video by visiting an unspecified URL. |