Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
–

389 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.41%—Cm2507 IP CameraAI18/9/202619/9/2026
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
AplazadaCrítica (9.8)0.58%—Xiongmai IP Camera Xm530AI11/9/202622/9/2026
Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full administrative control over the camera.
AplazadaCrítica (9.8)0.77%—Xiongmai IP Camera Xm530AI11/9/202622/9/2026
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream…
AplazadaAlta (7.5)0.74%—Xiongmai IP Camera Xm530AI11/9/202622/9/2026
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP…
AplazadaAlta (7.1)0.09%—C6 EAR CameraAIEarvisionAI9/9/202610/9/2026
The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and…
AplazadaMedia (6.7)0.12%—Android Camera MiddlewareAI7/9/20268/9/2026
In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11134622; Issue ID: MSV-8894.
AplazadaCrítica (9.1)0.40%—Trueview T18061 Wifi 3MP Robot Pan-tilt Security CameraAI17/8/202631/8/2026
An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component
AplazadaCrítica (9.3)2.4%—Puwell IP CameraAI4/8/20269/9/2026
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of…
AplazadaCrítica (9.3)0.83%—Puwell IP CameraAI4/8/20269/9/2026
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary…
Pendiente de análisisMedia (6.9)0.54%—Honeywell S35 Series CameraAIHoneywell 3M CameraAIHoneywell 5M CameraAIHoneywell 8M CameraAI+127/7/20263/9/2026
Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. Honeywell recommends…
Pendiente de análisisAlta (7.5)0.50%—Bosch Cpp13 IP CameraAIBosch Cpp14 IP CameraAI23/7/202623/7/2026
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
AplazadaMedia (5.3)0.34%—Hikvision CameraAI22/7/202622/7/2026
There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.
AplazadaAlta (7.2)0.54%—Hikvision CameraAI22/7/202622/7/2026
There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.
AplazadaAlta (7.7)0.38%—Hikvision CameraAI22/7/202622/7/2026
There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.
AplazadaAlta (7.5)0.42%—Hikvision Camera FirmwareAI22/7/202622/7/2026
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.
AplazadaMedia (6.6)0.36%—Hikvision CameraAI22/7/202622/7/2026
There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.
Pendiente de análisisAlta (7.5)0.15%—Lorex 2K Indoor Wi-fi Security CameraAI13/7/202614/7/2026
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. User interaction is not required to exploit this…
Pendiente de análisisAlta (7.5)0.41%—Lorex 2K Indoor Wi-fi Security CameraAI13/7/202614/7/2026
Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. Authentication is not required to exploit this vulnerability. The…
AplazadaCrítica (9.8)0.68%—Trueview Security Camera T18161AI7/7/202610/7/2026
Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.
AplazadaAlta (8.6)0.39%—H.view IP CameraAI26/6/202629/6/2026
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations…
AplazadaAlta (8.6)0.63%—H.view IP CameraAI26/6/202629/6/2026
A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated…
AplazadaMedia (6)0.24%—Shenzhen Liandian Communication Technology V380 IP CameraAI18/6/202622/6/2026
A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data.
AplazadaAlta (8.3)0.21%—Brickcom CamerasAI11/6/202617/6/2026
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.
AplazadaAlta (8.3)0.26%—Brickcom CamerasAI11/6/202617/6/2026
Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.
AplazadaCrítica (9.1)0.59%—KMW Cctv Security CameraAI29/5/202622/7/2026
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings.