Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.65%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this vulnerability by sending crafted login data with…
AplazadaCrítica (9.8)0.95%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this vulnerability by sending a crafted RTSP…
AplazadaCrítica (9.8)0.95%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this vulnerability by sending a crafted RTSP…
AplazadaCrítica (9.8)0.95%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AIThttpdAI26/6/202626/6/2026
An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by…
AplazadaAlta (8.6)0.43%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by…
AplazadaAlta (7.5)0.55%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing HTTP request body data. A remote attacker may exploit this vulnerability by sending a crafted request with…
AplazadaAlta (7.5)0.73%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of required HTTP request metadata before it is used by the affected components. A…
AplazadaAlta (7.5)0.55%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing filename values in multipart upload data. A remote attacker may exploit this vulnerability by sending a…
AplazadaAlta (7.5)0.35%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of multipart upload headers when processing certificate-related upload fields. A remote attacker may exploit this…
AplazadaAlta (7.5)1.5%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI component. A remote attacker may exploit this…
AnalizadaMedia (6.1)0.34%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS…
ModificadaCrítica (9.9)0.62%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.
ModificadaMedia (6.5)0.50%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability.
AnalizadaMedia (6.1)0.34%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.
ModificadaAlta (7.5)0.57%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.
ModificadaAlta (8.8)3.3%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.