Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 6.8% | — | Goahead Wireless IP Camera Wificam Firmware | 11/6/2019 | 17/6/2026 | An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI. | |
| Modificada | Alta (7.5) | 1.2% | — | Wireless IP Camera 360 | 26/2/2018 | 17/6/2026 | An issue was discovered on Wireless IP Camera 360 devices. Attackers can read recordings by navigating to /mnt/idea0 or /mnt/idea1 on the SD memory card. | |
| Modificada | Crítica (9.8) | 2.3% | — | Wireless IP Camera 360 | 26/2/2018 | 17/6/2026 | An issue was discovered on Wireless IP Camera 360 devices. Remote attackers can discover a weakly encoded admin password by connecting to TCP port 9527 and reading the password field of the debugging information, e.g., nTBCS19C corresponds to a password of 123456. | |
| Modificada | Alta (7.5) | 1.4% | — | Wireless IP Camera 360 | 26/2/2018 | 17/6/2026 | An issue was discovered on Wireless IP Camera 360 devices. Remote attackers can discover RTSP credentials by connecting to TCP port 9527 and reading the InsertConnect field. | |
| Modificada | Crítica (9.8) | 2.5% | — | Wireless IP Camera 360 | 26/2/2018 | 17/6/2026 | An issue was discovered on Wireless IP Camera 360 devices. A root account with a known SHA-512 password hash exists, which makes it easier for remote attackers to obtain administrative access via a TELNET session. | |
| Modificada | Crítica (9.8) | 35% | 💥 Exploit | Wificam Wireless IP Camera (p2p) Firmware | 25/4/2017 | 17/6/2026 | On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI. | |
| Modificada | Crítica (9.8) | 8.7% | 💥 Exploit | Wificam Wireless IP Camera (p2p) Firmware | 25/4/2017 | 17/6/2026 | Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Wificam Wireless IP Camera (p2p) Firmware | 25/4/2017 | 17/6/2026 | On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Wificam Wireless IP Camera (p2p) Firmware | 25/4/2017 | 17/6/2026 | Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pem inside the firmware, which allows attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Wificam Wireless IP Camera (p2p) Firmware | 25/4/2017 | 17/6/2026 | Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android application and a camera device, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (4.3) | 1.9% | — | Foscam Wireless IP Camera | 20/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web interface "WiFi scan" option in FOSCAM Wireless IP Cameras allows remote attackers to inject arbitrary web script or HTML via the SSID. |