Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.65% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this vulnerability by sending crafted login data with… | |
| Aplazada | Crítica (9.8) | 0.95% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this vulnerability by sending a crafted RTSP… | |
| Aplazada | Crítica (9.8) | 0.95% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this vulnerability by sending a crafted RTSP… | |
| Aplazada | Crítica (9.8) | 0.95% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AIThttpdAI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by… | |
| Aplazada | Alta (8.6) | 0.43% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by… | |
| Aplazada | Alta (7.5) | 0.55% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing HTTP request body data. A remote attacker may exploit this vulnerability by sending a crafted request with… | |
| Aplazada | Alta (7.5) | 0.73% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of required HTTP request metadata before it is used by the affected components. A… | |
| Aplazada | Alta (7.5) | 0.55% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing filename values in multipart upload data. A remote attacker may exploit this vulnerability by sending a… | |
| Aplazada | Alta (7.5) | 0.35% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of multipart upload headers when processing certificate-related upload fields. A remote attacker may exploit this… | |
| Aplazada | Alta (7.5) | 1.5% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI | 26/6/2026 | 26/6/2026 | An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI component. A remote attacker may exploit this… | |
| Analizada | Media (6.1) | 0.34% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS… | |
| Modificada | Crítica (9.9) | 0.62% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability. | |
| Modificada | Media (6.5) | 0.50% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability. | |
| Analizada | Media (6.1) | 0.34% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 0.57% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.3% | — | Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware | 4/5/2026 | 17/6/2026 | An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability. |