Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.23% | — | Pysoft Active Webcam | 16/1/2026 | 17/6/2026 | Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path by placing malicious executables in specific directory locations to gain administrative access. | |
| Aplazada | Media (6.4) | 0.19% | — | Wordpress Live Webcam Widget ShortcodeAI | 11/10/2025 | 17/6/2026 | The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.6) | 0.18% | — | Canon EOS Webcam Utility PROAI | 26/6/2025 | 17/6/2026 | Canon EOS Webcam Utility Pro for MAC OS version 2.3d (2.3.29) and earlier contains an improper directory permissions vulnerability. Exploitation of this vulnerability requires administrator access by a malicious user. An attacker could modify the directory, potentially resulting in code execution and ultimately… | |
| Aplazada | Media (6.1) | 0.18% | — | WebcamconsultAI | 18/1/2025 | 17/6/2026 | The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged… | |
| Aplazada | Media (4.4) | 0.23% | — | Logitech Mevo Webcam APPAI | 23/4/2024 | 17/6/2026 | Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code. | |
| Modificada | Alta (7.5) | 1.3% | — | Webcamserver Project Webcamserver | 10/5/2023 | 17/6/2026 | Buffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 allows a remote attacker to cause a denial of service via the WebcamServer.exe file. | |
| Modificada | Media (5.4) | 0.47% | — | React Webcam Project React Webcam | 20/3/2023 | 17/6/2026 | The React Webcam WordPress plugin through 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.5) | 0.37% | — | Fabulatech Webcam FOR Remote Desktop | 6/3/2023 | 17/6/2026 | A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42. It has been classified as problematic. Affected is the function 0x222018 in the library ftwebcam.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has… | |
| Modificada | Media (5.5) | 0.37% | — | Fabulatech Webcam FOR Remote Desktop | 6/3/2023 | 17/6/2026 | A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This issue affects some unknown processing in the library ftwebcam.sys of the component Global Variable Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host.… | |
| Modificada | Media (5.5) | 0.37% | — | Fabulatech Webcam FOR Remote Desktop | 6/3/2023 | 17/6/2026 | A vulnerability has been found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This vulnerability affects the function 0x222010/0x222018 in the library ftwebcam.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The… | |
| Modificada | Media (5.4) | 0.62% | — | Videowhisper Video Posts Webcam Recorder | 16/8/2021 | 17/6/2026 | The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos. | |
| Modificada | Media (6.1) | 1.3% | — | Videowhisper Webcam | 31/1/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhisper Webcam plugins for Drupal 7.x allows remote attackers to inject arbitrary web script or HTML via a URL to a crafted SVG file in the feed parameter. | |
| Modificada | Media (6.1) | 1.2% | — | Videowhisper Video Comments Webcam Recorder | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Crítica (9.8) | 2.6% | — | Foscam C1 Webcam Firmware | 21/6/2017 | 17/6/2026 | Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate device. | |
| Modificada | Media (4.3) | 1.6% | — | Videowhisper Video Posts Webcam Recorder | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder plugin 1.55.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Saschart Sascam Webcam Server | 28/6/2010 | 16/6/2026 | Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash) via a large number of requests with a long line, as demonstrated using a long GET request. | |
| Modificada | Media (5) | 4.8% | 💥 Exploit | Timhillone H264webcam | 21/6/2010 | 16/6/2026 | H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 32% | 💥 Exploit | Saschart Sascam Webcam Server | 5/8/2009 | 16/6/2026 | Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Get method and other unspecified methods. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Webcamxp | 6/1/2009 | 16/6/2026 | Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the URI. | |
| Modificada | Alta (9.4) | 4.5% | 💥 Exploit | Darkwet Webcam XP | 19/12/2008 | 16/6/2026 | Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and earlier allow remote attackers to cause a denial of service (device crash) and read portions of memory via (1) an invalid camnum parameter to the pocketpc component and (2) an invalid id parameter to… | |
| Modificada | Alta (10) | 1.6% | — | Menalto Gallery Webcam Module | 17/1/2008 | 16/6/2026 | Unspecified vulnerability in the WebCam module in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to a "proxied request." | |
| Modificada | Baja (2.1) | 0.32% | — | Willings WebcamWillings Webcam Lite | 16/5/2005 | 16/6/2026 | Willings WebCam and WebCam Lite 2.8 and earlier stores the password in memory in plaintext, which allows local users to gain sensitive information. | |
| Modificada | Media (4.3) | 1.2% | — | Webcamxp PRO | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WebcamXP PRO v2.16.468 and earlier allows remote attackers to inject arbitrary web script or HTML via the chat name, as demonstrated by using an IFRAME to redirect users to other sites. | |
| Modificada | Media (5) | 2.6% | — | PY Software Active Webcam | 2/5/2005 | 16/6/2026 | PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service via a request to a file on the floppy drive, as demonstrated using A:\a.txt. | |
| Modificada | Media (5) | 1.5% | — | PY Software Active Webcam | 2/5/2005 | 16/6/2026 | PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to determine the existence of files via an HTTP request with a full pathname, which produces different messages whether the file exists or not. |