Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.37% | — | Anpviz Ipc-d250AIAnpviz Ipc-d260AIAnpviz Ipc-b850AIAnpviz Ipc-d850AI+14 | 28/5/2024 | 17/6/2026 | Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B, YM800SV2, YM500L8, and YM200E10 firmware v3.2.2.2 and… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Anpviz Ipc-d250AIAnpviz Ipc-d260AIAnpviz Ipc-b850AIAnpviz Ipc-d850AI+13 | 28/5/2024 | 17/6/2026 | Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP GET request to the /playback/ URI. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B,… | |
| Aplazada | Media (4.6) | 0.19% | — | Anpviz Ipc-d250AIAnpviz Ipc-d260AIAnpviz Ipc-b850AIAnpviz Ipc-d850AI+14 | 28/5/2024 | 17/6/2026 | Certain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volume, speaker volume, LED lighting, NTP, motion detection, etc. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N,… | |
| Aplazada | Alta (7.5) | 0.40% | — | Anpviz Ipc-d250AIAnpviz Ipc-d260AIAnpviz Ipc-b850AIAnpviz Ipc-d850AI+14 | 28/5/2024 | 17/6/2026 | Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET request to /ConfigFile.ini or /config.xml URIs. This configuration file contains usernames and encrypted passwords (encrypted with a hardcoded key common to all devices). This affects IPC-D250,… | |
| Modificada | Alta (7.8) | 0.20% | — | Schneider-electric Hmibmuhi29d2801 FirmwareSchneider-electric Hmibmusi29d2801 FirmwareSchneider-electric Hmibmuci29d2w01 FirmwareSchneider-electric Hmibmu0i29d2001 Firmware+33 | 9/2/2022 | 17/6/2026 | A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer… | |
| Modificada | Media (5) | 4.2% | — | Brocade SilkwormBrocade Silkworm Fiber Channel SwitchEngenio Storage ControllerIBM Ds4100+2 | 4/9/2004 | 16/6/2026 | Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets. |