Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
117 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 1.7% | — | C-mor Video SurveillanceAI | 15/9/2026 | 22/9/2026 | The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml. | |
| Aplazada | Media (6.1) | 0.91% | — | C-mor Video SurveillanceAI | 15/9/2026 | 22/9/2026 | Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component | |
| Aplazada | Alta (8.9) | 0.32% | — | Siveillance Control PRO V3.0AISiveillance Control PRO V4.0AISiveillance Control V3.0AISiveillance Control V4.0AI | 8/9/2026 | 8/9/2026 | A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an… | |
| Analizada | Baja (2.7) | 0.25% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. | |
| Analizada | Media (4.9) | 0.34% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. | |
| Analizada | Baja (2.7) | 0.25% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. | |
| Analizada | Media (4.9) | 0.23% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. | |
| Analizada | Media (4.9) | 0.34% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. | |
| Analizada | Baja (2.7) | 0.33% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. | |
| Aplazada | Alta (8.5) | 0.11% | — | Argus Surveillance DVRAI | 10/5/2026 | 25/7/2026 | Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the… | |
| Analizada | Baja (2.1) | 0.50% | — | Tiandy Video Surveillance System Firmware | 9/3/2026 | 17/6/2026 | A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile of the file /src/com/tiandy/easy7/core/rest/CLS_REST_File.java. The manipulation of the argument fileName leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Aplazada | Alta (8.1) | 0.58% | — | Ancorathemes VeilAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Veil veil allows PHP Local File Inclusion.This issue affects Veil: from n/a through <= 1.9. | |
| Aplazada | Baja (2.1) | 0.36% | — | Tiandy Video Surveillance SystemAI | 23/2/2026 | 17/6/2026 | A security flaw has been discovered in Tiandy Video Surveillance System 视频监控平台 7.17.0. This impacts the function downloadImage of the file /com/tiandy/easy7/core/bo/CLSBODownLoad.java. Performing a manipulation of the argument urlPath results in server-side request forgery. The attack is possible to be carried out… | |
| Aplazada | Crítica (10) | 1.3% | — | Cyclope Employee Surveillance SolutionAI | 8/8/2025 | 16/6/2026 | Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to inject arbitrary SQL statements. This can be leveraged to write and execute a malicious PHP file on… | |
| Aplazada | Media (5.1) | 0.14% | — | I-pro Surveillance CameraAI | 6/6/2025 | 17/6/2026 | Cross-site request forgery vulnerability exists in surveillance cameras provided by i-PRO Co., Ltd.. If a user views a crafted page while logged in to the affected product, unintended operations may be performed. | |
| Aplazada | Media (6.8) | 0.17% | — | I-pro Configuration ToolAII-pro Surveillance CamerasAII-pro RecordersAI | 24/4/2025 | 17/6/2026 | Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameras and recorders. | |
| Analizada | Media (4.3) | 0.40% | — | Synology Surveillance Station | 4/12/2024 | 17/6/2026 | Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors. | |
| Analizada | Media (4.3) | 0.40% | — | Synology Surveillance Station | 4/12/2024 | 17/6/2026 | Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to to perform limited actions on the alerting function via unspecified vectors. | |
| Analizada | Alta (7.2) | 2.6% | — | C-mor Video Surveillance | 9/10/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS command injection attacks. It was found out that different functionality is vulnerable to OS command injection attacks, for example for generating new… | |
| Analizada | Media (6.1) | 1.00% | — | C-mor Video Surveillance | 5/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web interface is vulnerable to reflected cross-site scripting (XSS) attacks. It was found out that different functions are prone to reflected cross-site scripting attacks due to insufficient user input… | |
| Analizada | Alta (8.8) | 0.67% | — | C-mor Video Surveillance | 5/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example login credentials of cameras, is stored in cleartext. Thus, an attacker with filesystem access, for example exploiting a path traversal attack,… | |
| Analizada | Alta (8.8) | 0.92% | — | C-mor Video Surveillance | 5/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance PHP code, to the C-MOR system. By analyzing the C-MOR web interface, it was found out that the upload functionality for backup files allows an… | |
| Analizada | Alta (7.1) | 1.3% | — | C-mor Video Surveillance | 5/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the C-MOR system via a path traversal attack. It was found out that different functionalities are vulnerable to path traversal attacks, due to insufficient user… | |
| Analizada | Alta (8.8) | 0.92% | — | C-mor Video Surveillance | 5/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo without having to enter… | |
| Analizada | Media (6.8) | 0.39% | — | C-mor Video Surveillance | 4/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is vulnerable to cross-site request forgery (CSRF) attacks. The C-MOR web interface offers no protection against cross-site request forgery (CSRF) attacks. |