Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.21%—Brickcom CamerasAI11/6/202617/6/2026
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.
AplazadaAlta (8.3)0.26%—Brickcom CamerasAI11/6/202617/6/2026
Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.
AplazadaCrítica (9.1)0.59%—Zkteco Cctv CamerasAI20/5/202620/7/2026
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.
Pendiente de análisisCrítica (9.2)0.39%—Milesight Aiot CamerasAI28/4/202625/7/2026
Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
Pendiente de análisisAlta (7.3)0.28%—Milesight Aiot CamerasAI27/4/202625/7/2026
A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.
AplazadaAlta (8.7)0.47%—Flir Thermal Traffic CamerasAI24/12/202517/6/2026
FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming URLs without authentication.
AplazadaCrítica (9.3)0.33%—Flir Thermal Traffic CamerasAI24/12/202517/6/2026
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of…
AplazadaMedia (6.8)0.23%—Honeywell S35 Series CamerasAI27/10/202517/6/2026
Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeywell also recommends updating to the most recent version of this product, service…
AplazadaAlta (8.3)0.32%—Avtech IP CamerasAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.
AplazadaMedia (6.8)0.17%—I-pro Configuration ToolAII-pro Surveillance CamerasAII-pro RecordersAI24/4/202517/6/2026
Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameras and recorders.
ModificadaAlta (7.8)0.26%—Huddlycameraservices1/12/202317/6/2026
An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers to manipulate files and escalate privileges via RollingFileAppender.DeleteFile method performed by the log4net library.
ModificadaAlta (7.8)0.32%—Huddlycameraservice1/12/202317/6/2026
DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the installation of the service in a directory that grants write privileges to standard users, allows attackers to manipulate files, execute arbitrary code, and escalate privileges.
ModificadaCrítica (9.8)5.3%—Boschsecurity Nbn-498 Dinion2x Day/night IP Cameras Firmware18/2/202017/6/2026
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.
ModificadaCrítica (9.8)2.3%—Hikvision IP Cameras13/8/201817/6/2026
A buffer overflow vulnerability in the web server of some Hikvision IP Cameras allows an attacker to send a specially crafted message to affected devices. Due to the insufficient input validation, successful exploit can corrupt memory and lead to arbitrary code execution or crash the process.
ModificadaMedia (4.3)3.6%—Axis M10 Series Network Cameras FirmwareAxis M1054 Network Camera12/2/201316/6/2026
Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the pageTitle parameter to admin/showReport.shtml.