Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2554▼ 405 respecto a la semana anterior
Críticas / altas1317▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.39%—Hikvision Nvr-216mh-c(d) FirmwareHikvision Nvr-216mh-c/16p(d) FirmwareHikvision Nvr-208mh-c/8p(d) FirmwareHikvision Nvr-104mh-c/4p(d) Firmware+3623/11/202317/6/2026
There is a buffer overflow in the password recovery feature of Hikvision NVR/DVR models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.
ModificadaAlta (7.8)0.32%—Qvis DVR FirmwareQvis NVR Firmware18/7/202217/6/2026
In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a Sudo misconfiguration.
ModificadaCrítica (9.8)9.2%—Qvis DVR FirmwareQvis NVR Firmware18/7/202217/6/2026
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
ModificadaMedia (6.5)0.64%—Castel Nextgen DVR Firmware4/6/202017/6/2026
Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request will succeed.
ModificadaAlta (8.1)1.1%—Castel Nextgen DVR Firmware4/6/202017/6/2026
Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials.
ModificadaMedia (6.5)1.2%—Castel Nextgen DVR Firmware4/6/202017/6/2026
Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to check that a request was submitted by an administrator. Consequently, a normal user can perform actions including, but not limited to, creating/modifying the file store, creating/modifying…
ModificadaAlta (8.8)2.0%—Castel Nextgen DVR Firmware4/6/202017/6/2026
Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Adminstrator/Users/Edit/:UserId fails to check that the request was submitted by an Administrator. This allows a normal user to escalate their privileges by adding additional roles to their…
ModificadaAlta (8.8)1.6%—Icatchinc DVR Firmware15/4/202017/6/2026
iCatch DVR firmware before 20200103 do not validate function parameter properly, resulting attackers executing arbitrary command.
ModificadaCrítica (9.8)13%—Avtech Avn801 DVR Firmware27/12/201916/6/2026
AVTECH AVN801 DVR has a security bypass via the administration login captcha
ModificadaAlta (8.1)3.7%—Honeywell Enterprise DVR FirmwareHoneywell Maxpro NVR Hybrid SE FirmwareHoneywell Maxpro NVR Hybrid XE FirmwareHoneywell Maxpro NVR SE Firmware+311/9/201717/6/2026
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control…
ModificadaAlta (7.5)70%—Dahuasecurity DVR Firmware11/7/201416/6/2026
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.
ModificadaAlta (9)6.0%—Avtech Avn801 DVR FirmwareAvtech Avn801 DVR3/3/201416/6/2026
Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the Network.SMTP.Receivers parameter.
ModificadaAlta (9)6.0%—Avtech Avn801 DVR FirmwareAvtech Avn801 DVR3/3/201416/6/2026
Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the URI in an RTSP SETUP request.
ModificadaAlta (7.8)10%—TVT DVRTVT DVR Firmware2/11/201316/6/2026
Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI.