Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.46%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
AplazadaAlta (7.5)0.57%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.
AplazadaMedia (6.5)0.55%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.
AplazadaAlta (7.5)0.55%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
AplazadaAlta (7.5)0.46%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections.
AplazadaCrítica (9.4)0.51%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.
AplazadaMedia (4.9)0.44%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.
AplazadaMedia (4.9)0.44%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.
AplazadaAlta (7.2)0.54%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update.
AplazadaMedia (4.9)0.44%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.
AplazadaMedia (4.9)0.44%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.
AplazadaMedia (4.9)0.44%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.
AplazadaCrítica (9.8)0.48%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
AplazadaAlta (8.8)0.65%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.
AplazadaAlta (7.2)0.70%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.
AplazadaAlta (7.2)0.70%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
AplazadaAlta (7.2)0.70%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.
AplazadaAlta (7.2)0.70%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.
AplazadaAlta (7.2)0.54%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.
AplazadaAlta (8.8)0.42%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.
AplazadaMedia (6.5)0.37%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.
AplazadaMedia (6.5)0.34%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.
AplazadaMedia (6.5)0.41%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.
AplazadaCrítica (9.8)0.65%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this vulnerability by sending crafted login data with…
AplazadaCrítica (9.8)0.95%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AI26/6/202626/6/2026
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this vulnerability by sending a crafted RTSP…