Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.7) | 0.14% | — | Foscam Video Management SystemAI | 20/2/2026 | 17/6/2026 | Foscam Video Management System 1.1.6.6 contains a buffer overflow vulnerability in the UID field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 5000-character buffer into the UID parameter during device addition to trigger an application crash when… | |
| Aplazada | Media (4.6) | 0.25% | — | Foscam Video Management SystemAI | 18/2/2026 | 17/6/2026 | Foscam Video Management System 1.1.4.9 contains a denial of service vulnerability in the username input field that allows attackers to crash the application. Attackers can overwrite the username with a 520-byte buffer of repeated 'A' characters to trigger an application crash during device login. | |
| Analizada | Baja (3.5) | 0.29% | — | Maximize Simple Video Management System | 13/2/2025 | 17/6/2026 | The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.1) | 0.35% | — | Maximize Simple Video Management SystemAI | 7/1/2025 | 17/6/2026 | The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analytics_video' parameter in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Media (5.9) | 0.56% | — | Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+10 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks. | |
| Modificada | Alta (8.8) | 0.75% | — | Video Management System Project Video Management System | 29/6/2023 | 17/6/2026 | An issue was discovered with the JSESSION IDs in Xiamen Si Xin Communication Technology Video management system 3.1 thru 4.1 allows attackers to gain escalated privileges. | |
| Modificada | Alta (7.7) | 0.46% | — | Bosch Video Management SystemBosch Video Management System ViewerBosch Divar IP 3000 FirmwareBosch Divar IP 6000 Firmware+5 | 15/6/2023 | 17/6/2026 | Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request. | |
| Modificada | Media (5.9) | 0.36% | — | Bosch Video Management SystemBosch Videojet Decoder 7513 Firmware | 30/9/2022 | 17/6/2026 | Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or… | |
| Modificada | Alta (7.5) | 1.4% | — | Milesight Video Management Systems Firmware | 15/9/2022 | 17/6/2026 | This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due to improper input handling at camera’s web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted network camera.… | |
| Modificada | Alta (7.2) | 1.4% | — | Bosch Video Management SystemBosch Video Recording ManagerBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 8000 Firmware | 8/12/2021 | 17/6/2026 | A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000). | |
| Modificada | Media (6.5) | 0.83% | — | Bosch Video Management SystemBosch Video Recording Manager | 8/12/2021 | 17/6/2026 | By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations of the DIVAR IP and BVMS with VRM installed. | |
| Modificada | Media (6.1) | 0.51% | — | Bosch Video Management SystemBosch Video Recording Manager | 8/12/2021 | 17/6/2026 | An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed. | |
| Modificada | Alta (7.5) | 1.0% | — | Bosch Video Management SystemBosch Video Recording ManagerBosch Access Easy Controller FirmwareBosch Access Professional Edition+2 | 8/12/2021 | 17/6/2026 | An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering… | |
| Modificada | Alta (7.5) | 2.3% | — | Revisorlab Video Management System | 19/10/2021 | 17/6/2026 | Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of restricted directory on the remote server. This could lead to the disclosure of sensitive data on… | |
| Modificada | Alta (7.8) | 0.33% | — | Bosch Video Management SystemBosch Video Management System Viewer | 25/3/2021 | 17/6/2026 | Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potentially allows an attacker to execute arbitrary code on a victim's system. This affects both the installer as well as the installed application. This also affects Bosch… | |
| Modificada | Crítica (9.8) | 0.98% | — | Bosch Video Recording ManagerBosch Divar IP 5000 FirmwareBosch Video Management System | 26/2/2021 | 17/6/2026 | Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified authentication checks. Prior releases of… | |
| Modificada | Media (6.5) | 0.99% | — | Tyco Victor Video Management SystemJohnsoncontrols C-cure 9000 Firmware | 21/5/2020 | 17/6/2026 | During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file. The install log file persists after the installation. | |
| Modificada | Crítica (9.8) | 3.6% | — | Bosch Video Management System Mobile Video ServiceBosch Divar IP 3000 FirmwareBosch Divar IP 7000 Firmware | 7/2/2020 | 17/6/2026 | Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000… | |
| Modificada | Alta (7.5) | 1.7% | — | Bosch Video Management System ViewerBosch Video Management System | 7/2/2020 | 17/6/2026 | A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS… | |
| Modificada | Media (6.5) | 1.3% | — | Bosch Video Management System ViewerBosch Video Management System | 6/2/2020 | 17/6/2026 | A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS… | |
| Modificada | Crítica (9.1) | 1.5% | — | Bosch Access Professional EditionBosch Video ClientBosch Video Management SystemBosch Building Integration System+7 | 29/5/2019 | 17/6/2026 | A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC)… | |
| Modificada | Crítica (9.8) | 2.0% | — | Bosch Access Professional EditionBosch Video ClientBosch Video Management SystemBosch Building Integration System+9 | 29/5/2019 | 17/6/2026 | A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Video Recording Manager (VRM), Video Streaming Gateway (VSG), Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition… | |
| Modificada | Media (6.5) | 1.4% | — | Bosch Divar IP 2000 FirmwareBosch Divar IP 5000 FirmwareBosch Video Management SystemBosch Video Recording Manager | 13/5/2019 | 17/6/2026 | A Path Traversal vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote authorized user to access arbitrary files on the system via the network interface. Affected hardware products: Bosch DIVAR IP 2000 (vulnerable versions: 3.10;… | |
| Modificada | Media (6.1) | 1.1% | — | Bosch Divar IP 2000 FirmwareBosch Divar IP 5000 FirmwareBosch Video Management SystemBosch Video Recording Manager | 13/5/2019 | 17/6/2026 | An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote attacker to redirect users to an arbitrary URL. Affected hardware products: Bosch DIVAR IP 2000 (vulnerable versions: 3.10; 3.20; 3.21; 3.50; 3.51; 3.55; 3.60;… | |
| Modificada | Alta (7.5) | 0.75% | — | Mirasys Video Management System | 12/10/2017 | 17/6/2026 | Mirasys Video Management System (VMS) 6.x before 6.4.6, 7.x before 7.5.15, and 8.x before 8.1.1 has a login process in which cleartext data is sent from a server to a client, and not all of this data is required for the client functionality. |