Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.4) | 0.78% | — | Milestonesys XprotectAI | 14/7/2026 | 11/8/2026 | Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service. | |
| Aplazada | Media (5.3) | 0.21% | — | Milestone Systems Xprotect VMSAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management Server to have full read/write access to MIP Webhooks API. | |
| Aplazada | Media (5.5) | 0.24% | — | Milestonesys XprotectAI | 15/4/2025 | 17/6/2026 | Milestone Systems has discovered a security vulnerability in Milestone XProtect installer that resets system configuration password after the upgrading from older versions using specific installers. The system configuration password is an additional, optional protection that is enabled on the Management Server. To… | |
| Aplazada | Media (5.2) | 0.15% | — | Milestonesys XprotectAI | 19/12/2024 | 17/6/2026 | Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in the Recording Server under specific conditions. | |
| Aplazada | Alta (7.3) | 0.23% | — | Milestone Xprotect Device PackAI | 8/10/2024 | 17/6/2026 | A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on Recording Server under strict conditions. | |
| Modificada | Alta (8.1) | 4.0% | — | Milestonesys XprotectSiemens Siveillance VMS | 30/4/2018 | 17/6/2026 | The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.a) to 2018 R1 (12.1a) contains .NET Remoting endpoints that are vulnerable to deserialization attacks resulting in remote code execution. |