Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.48%—Selea CarplateserverAI31/12/202523/9/2026
Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication through the /cps/ endpoint and modify server configuration, including changing…
AplazadaAlta (8.5)0.15%—Selea CarplateserverAI31/12/202523/9/2026
Selea CarPlateServer 4.0.1.6 contains an unquoted service path vulnerability in the Windows service configuration that allows local users to potentially execute code with elevated privileges. Attackers can exploit the service's unquoted binary path by inserting malicious code in the system root path that could execute…
AnalizadaCrítica (9.3)0.52%—Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+89/12/202517/6/2026
Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocumented page. Attackers can exploit the hidden endpoint by using the hard-coded password 'Selea781830' to enable configuration upload and overwrite device settings.
ModificadaAlta (8.5)0.25%—Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+89/12/202517/6/2026
Selea Targa IP OCR-ANPR Camera contains a cross-site request forgery vulnerability that allows attackers to create administrative users without authentication. Attackers can craft a malicious web page that submits a form to add a new admin user with full system privileges when a logged-in user visits the page.
AnalizadaMedia (5.1)0.30%—Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+89/12/202517/6/2026
Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.
AnalizadaCrítica (9.3)2.6%—Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+89/12/202517/6/2026
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion…
AnalizadaAlta (8.7)0.47%—Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+89/12/202517/6/2026
Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentication. Attackers can directly connect to RTP/RTSP or M-JPEG streams by requesting specific endpoints like p1.mjpg or p1.264 to view camera footage.