Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | Hikvision Hikcentral Access ControlAI | 10/9/2026 | 10/9/2026 | There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access. | |
| Aplazada | Media (6.1) | 0.41% | — | Hikvision IntercomAI | 10/9/2026 | 18/9/2026 | Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue cards. | |
| Aplazada | Alta (7.2) | 0.92% | — | Hikvision Networking ProductsAI | 31/7/2026 | 28/8/2026 | Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |
| Aplazada | Media (5.3) | 0.34% | — | Hikvision CameraAI | 22/7/2026 | 22/7/2026 | There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory. | |
| Aplazada | Alta (7.2) | 0.54% | — | Hikvision CameraAI | 22/7/2026 | 22/7/2026 | There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets. | |
| Aplazada | Alta (7.7) | 0.38% | — | Hikvision CameraAI | 22/7/2026 | 22/7/2026 | There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets. | |
| Aplazada | Alta (7.5) | 0.42% | — | Hikvision Camera FirmwareAI | 22/7/2026 | 22/7/2026 | Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data. | |
| Aplazada | Media (6.6) | 0.36% | — | Hikvision CameraAI | 22/7/2026 | 22/7/2026 | There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH. | |
| Pendiente de análisis | Alta (7.2) | 1.1% | — | Hikvision SwitchAI | 9/5/2026 | 24/7/2026 | Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary… | |
| Pendiente de análisis | Media (6.8) | 0.28% | — | Hikvision Hikcentral ProfessionalAI | 9/5/2026 | 25/7/2026 | There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission. | |
| Aplazada | Alta (7.2) | 0.91% | — | Hikvision Wireless Access PointAI | 30/1/2026 | 17/6/2026 | Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |
| Aplazada | Alta (8.8) | 0.35% | — | Hikvision NVRAIHikvision DVRAIHikvision CVRAIHikvision IPCAI | 13/1/2026 | 9/7/2026 | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device. | |
| Modificada | Alta (8.8) | 0.47% | — | Hikvision Ds-k1t331 FirmwareHikvision Ds-k1t341a FirmwareHikvision Ds-k1t341b FirmwareHikvision Ds-k1t671 Firmware+24 | 13/1/2026 | 9/7/2026 | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device. | |
| Analizada | Media (6.8) | 0.35% | — | Hikvision Ds-7104hghi-f1 FirmwareHikvision Ds-7204hghi-f1 Firmware | 19/12/2025 | 17/6/2026 | There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and run a series of commands. | |
| Analizada | Media (6.2) | 0.21% | — | Hikvision Ds-7104hghi-f1 FirmwareHikvision Ds-7204hghi-f1 Firmware | 19/12/2025 | 17/6/2026 | There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shell environment. | |
| Aplazada | Alta (8.3) | 1.3% | — | Hikvision CsmpAIHikvision Isecure CenterAI | 22/10/2025 | 17/6/2026 | Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory traversal, as exploited in the wild in 2024 and 2025. | |
| Aplazada | Alta (8.3) | 19% | — | Hikvision CsmpAIHikvision Isecure CenterAI | 22/10/2025 | 1/10/2026 | Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025. | |
| Aplazada | Crítica (9.8) | 1.4% | — | Hikvision Isecure CenterAI | 17/10/2025 | 17/6/2026 | Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges and execute arbitrary commands on the system.iSecure Center is software released for China's domestic market only, with… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Hikvision Isecure CenterAI | 17/10/2025 | 17/6/2026 | Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to be uploaded, attackers may upload malicious files to the server. iSecure Center is software released for China's domestic market only, with no overseas release. | |
| Aplazada | Alta (8.6) | 0.45% | — | Hikvision Hikcentral ProfessionalAI | 29/8/2025 | 17/6/2026 | There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission. | |
| Aplazada | Media (5.3) | 0.33% | — | Hikvision Hikcentral FocsignAI | 29/8/2025 | 17/6/2026 | There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (4.7) | 0.35% | — | Hikvision Hikcentral Master LiteAI | 29/8/2025 | 17/6/2026 | There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data. | |
| Aplazada | Crítica (10) | 22% | — | Hikvision Integrated Security Management PlatformAIAlibaba FastjsonAI | 2/7/2025 | 17/6/2026 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger… | |
| Aplazada | Alta (8.7) | 0.85% | — | Hikvision Streaming Media Management ServerAI | 1/7/2025 | 17/6/2026 | Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory… | |
| Aplazada | Alta (7.5) | 0.62% | — | Hikvision Ds-2cd1321-iAI | 27/6/2025 | 17/6/2026 | An issue in Hikvision DS-2CD1321-I V5.7.21 build 230819 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the endpoint /ISAPI/Security/challenge. The vendor has stated that upgrading to V5.7.23_SP2 fixes the issue. |