Vulnerabilities
Summary — last 7 days
New vulnerabilities2,768▼ 449 vs. last week
Critical / high1,325▼ 128 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)268▼ 240 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.5) | 2.3% | — | Foscam C1 Lite FirmwareFoscam C1 FirmwareFoscam Fi9800p FirmwareFoscam Fi9821ep Firmware+28 | 7/9/2018 | 6/17/2026 | Stack-based buffer overflow in the getSWFlag function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1… | |
| Modified | High (7.2) | 4.5% | — | Foscam C1 Lite FirmwareFoscam C1 FirmwareFoscam Fi9800p FirmwareFoscam Fi9821ep Firmware+28 | 7/9/2018 | 6/17/2026 | The setSystemTime function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47 and… | |
| Modified | High (7.5) | 2.6% | — | Foscam C1 Lite FirmwareFoscam C1 FirmwareFoscam Fi9800p FirmwareFoscam Fi9821ep Firmware+28 | 7/9/2018 | 6/17/2026 | Directory traversal vulnerability in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47… | |
| Modified | High (8.1) | 1.7% | 💥 PoC | Foscam C1Foscam C1 LiteFoscam C2Foscam Fi9800xe+8 | 4/10/2017 | 6/17/2026 | Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation. |