Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
–

34 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.54%—Kingdom Communication Associated Smart Video Intercom SystemAI11/9/202611/9/2026
Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.
AplazadaAlta (8.7)0.51%—Kingdom Communication Associated Smart Video Intercom SystemAI11/9/202611/9/2026
Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
AplazadaMedia (6.9)0.44%—Kingdom Communication Associated Smart Video Intercom SystemAI11/9/202611/9/2026
Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.
AplazadaMedia (6.1)0.41%—Hikvision IntercomAI10/9/202618/9/2026
Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue cards.
AplazadaMedia (6.5)0.33%—Parani M10 Motorcycle IntercomAI13/4/202617/6/2026
An issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause a Denial of Service (DoS) via supplying crafted RFCOMM frames.
AplazadaMedia (4.3)0.20%—SAP Fiori APP Intercompany Balance ReconciliationAI27/1/202617/6/2026
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on confidentiality, integrity and availability are not impacted.
AplazadaAlta (8.1)0.30%—SAP Fiori APP Intercompany Balance ReconciliationAI13/1/202617/6/2026
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has high impact on confidentiality and integrity of the application ,availability is not impacted.
AplazadaMedia (6.6)0.22%—SAP Fiori APP Intercompany Balance ReconciliationAI13/1/202617/6/2026
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.
AplazadaMedia (5.1)0.18%—SAP Fiori APP Intercompany Balance ReconciliationAI13/1/202617/6/2026
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.
AplazadaMedia (4.3)0.21%—SAP Fiori APP Intercompany Balance ReconciliationAI13/1/202617/6/2026
Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access information which would otherwise be restricted. This has low impact on confidentiality of the application, integrity and availability are not impacted.
AplazadaMedia (4.3)0.13%—SAP Fiori APP Intercompany Balance ReconciliationAI13/1/202617/6/2026
Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacker could execute state?changing actions using an inappropriate request type, this deviation from expected request semantics may allow an attacker to trigger unintended actions on behalf of an…
AplazadaMedia (6.8)0.15%—IntercomAI24/12/202517/6/2026
Beward Intercom 2.3.1 contains a credentials disclosure vulnerability that allows local attackers to access plain-text authentication credentials stored in an unencrypted database file. Attackers can read the BEWARD.INTERCOM.FDB file to extract usernames and passwords, enabling unauthorized access to IP cameras and…
AplazadaCrítica (9.8)1.2%—UI Unifi Access Reader PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access G3 Reader PROAIUI Unifi Access IntercomAI+24/8/202517/6/2026
An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network. Affected Products: UniFi Access Reader Pro (Version 2.14.21 and earlier) UniFi Access G2 Reader Pro (Version 1.10.32 and earlier) UniFi Access G3 Reader Pro…
AnalizadaCrítica (9.3)0.57%—Cyberdata 011209 SIP Emergency Intercom Firmware9/6/202517/6/2026
CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.
AnalizadaMedia (6.9)0.37%—Cyberdata 011209 SIP Emergency Intercom Firmware9/6/202517/6/2026
CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.
AnalizadaAlta (8.7)0.42%—Cyberdata 011209 SIP Emergency Intercom Firmware9/6/202517/6/2026
CyberData 011209 Intercom does not properly store or protect web server admin credentials.
AnalizadaAlta (8.7)0.41%—Cyberdata 011209 SIP Emergency Intercom9/6/202517/6/2026
CyberData 011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system disruption.
AnalizadaCrítica (9.3)0.52%—Cyberdata 011209 SIP Emergency Intercom Firmware9/6/202517/6/2026
CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.
AplazadaBaja (2.2)0.44%—UI Unifi Connect EV StationAIUI Unifi Connect EV Station PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access Reader PROAI+47/5/202417/6/2026
An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version 1.1.18 and earlier) UniFi Access G2 Reader…
AplazadaAlta (8.8)0.79%—Shibang Communications IP Network Intercom Broadcasting SystemAI17/4/202417/6/2026
File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitrary code via the my_parser.php component.
AplazadaMedia (5.4)0.65%—Shibang Communications IP Network Intercom Broadcasting SystemAI3/4/202417/6/2026
A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System 1.0. This affects an unknown part of the file /php/busyscreenshotpush.php. The manipulation of the argument jsondata[callee]/jsondata[imagename] leads to path traversal: '../filedir'. It is possible…
ModificadaCrítica (9.8)89%—Hikvision Intercom Broadcast System17/12/202317/6/2026
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has…
ModificadaMedia (6.5)0.98%—Hikvision Intercom Broadcast System17/12/202317/6/2026
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been classified as problematic. This affects an unknown part of the file access/html/system.html of the component Log File Handler. The manipulation leads to information disclosure. The exploit has been disclosed to…
ModificadaAlta (7.5)70%—Hikvision Intercom Broadcast System17/12/202317/6/2026
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. Affected by this issue is some unknown functionality of the file /php/exportrecord.php. The manipulation of the argument downname with the input C:\ICPAS\Wnmp\WWW\php\conversion.php leads to…
ModificadaAlta (7.5)1.9%—Intercom12/11/201917/6/2026
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).