Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
–

84 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.41%—Cm2507 IP CameraAI18/9/202619/9/2026
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
AplazadaCrítica (9.8)0.58%—Xiongmai IP Camera Xm530AI11/9/202622/9/2026
Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full administrative control over the camera.
AplazadaCrítica (9.8)0.77%—Xiongmai IP Camera Xm530AI11/9/202622/9/2026
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream…
AplazadaAlta (7.5)0.74%—Xiongmai IP Camera Xm530AI11/9/202622/9/2026
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP…
AplazadaCrítica (9.3)2.4%—Puwell IP CameraAI4/8/20269/9/2026
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of…
AplazadaCrítica (9.3)0.83%—Puwell IP CameraAI4/8/20269/9/2026
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary…
Pendiente de análisisAlta (7.5)0.50%—Bosch Cpp13 IP CameraAIBosch Cpp14 IP CameraAI23/7/20261/10/2026
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
AplazadaAlta (8.6)0.39%—H.view IP CameraAI26/6/202629/6/2026
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations…
AplazadaAlta (8.6)0.63%—H.view IP CameraAI26/6/202629/6/2026
A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated…
AplazadaMedia (6)0.24%—Shenzhen Liandian Communication Technology V380 IP CameraAI18/6/202622/6/2026
A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data.
Pendiente de análisisAlta (7.2)0.33%—LSC Smart Indoor IP CameraAI25/3/202617/6/2026
A buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handling of the Time Zone (TZ) parameter within the ONVIF configuration interface. The time zone (TZ) parameter does not have its length properly validated before being copied into a fixed-size buffer…
AplazadaAlta (8.7)1.2%—Meritlilin IP CameraAI12/1/202617/6/2026
Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
AnalizadaAlta (8.8)0.34%—LSC Smart Connect Indoor IP Camera Firmware22/12/202517/6/2026
LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.
AplazadaAlta (8.7)0.94%—JVC Vn-t IP CameraAI12/11/202517/6/2026
JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.
ModificadaAlta (7.5)0.48%—Simicam IP Camera FirmwareKeview IP Camera FirmwareAsecam IP Camera Firmware12/11/202517/6/2026
Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication.
AplazadaAlta (8.3)0.32%—Avtech IP CamerasAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.
AplazadaMedia (6.9)0.62%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.
AplazadaCrítica (9.4)1.8%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are directly embedded into system commands without proper sanitation.…
AplazadaCrítica (9.4)1.5%—Avtech DVRAIAvtech NVRAIAvtech IP CameraAI1/7/202517/6/2026
An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke the DoShellCmd operation, passing arbitrary input via the strCmd parameter. This input is executed directly by the system…
AplazadaMedia (6.9)0.63%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.
AplazadaMedia (5.1)0.28%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user…
AplazadaMedia (6.5)0.30%—LSC Smart Connect Indoor IP CameraAI5/11/202417/6/2026
The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user…
AplazadaAlta (8.7)0.49%—D3dsecurity IP Camera D8801AI4/10/202417/6/2026
** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-Time Streaming Protocol (RTSP) version for live video streaming. A remote attacker could exploit this vulnerability by crafting a RTSP packet leading to unauthorized access to live feed of the…
AplazadaAlta (8.7)0.36%—D3dsecurity IP Camera D8801AI4/10/202417/6/2026
** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentication scheme of the HTTP header protocol where authorization tag contain a Base-64 encoded username and password. A remote attacker could exploit this vulnerability by crafting a HTTP packet leading…
ModificadaAlta (7.5)0.59%—Biltema Baby Camera FirmwareBiltema IP Camera Firmware3/2/202317/6/2026
Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive information.