Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations. | |
| Modificada | Crítica (9.8) | 3.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource. | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the customer has not configured 10 actual user accounts. | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory. | |
| Modificada | Crítica (9.8) | 3.2% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password. |