Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.34% | — | LSC Smart Connect Indoor IP Camera Firmware | 22/12/2025 | 17/6/2026 | LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh. | |
| Modificada | Alta (7.5) | 0.48% | — | Simicam IP Camera FirmwareKeview IP Camera FirmwareAsecam IP Camera Firmware | 12/11/2025 | 17/6/2026 | Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication. | |
| Modificada | Alta (7.5) | 0.59% | — | Biltema Baby Camera FirmwareBiltema IP Camera Firmware | 3/2/2023 | 17/6/2026 | Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive information. | |
| Modificada | Alta (7.5) | 3.7% | — | Netwavepr Indoor IP Camera FirmwareNetwavepr Outdoor IP Camera Firmware | 10/6/2022 | 17/6/2026 | There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password). | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Video Surveillance 7000 IP Camera Firmware | 18/8/2021 | 17/6/2026 | A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for the Cisco Video Surveillance 7000 Series IP Cameras firmware could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper management of memory resources, referred to… | |
| Modificada | Media (6.1) | 0.75% | — | Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware | 30/3/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in the FTP settings page to the "goform/formSetFtpCfg" settings page. | |
| Modificada | Media (6.2) | 0.45% | — | Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware | 30/3/2021 | 17/6/2026 | An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via editing the 'recdata.db' file to call a specially crafted GoAhead ASP-file on the SD card. | |
| Modificada | Alta (8.8) | 1.3% | — | Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware | 30/3/2021 | 17/6/2026 | An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. Authenticated attackers with the "Operator" Privilege can gain admin privileges via a crafted request to '/goform/formUserMng'. | |
| Modificada | Alta (7.5) | 1.3% | — | Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware | 30/3/2021 | 17/6/2026 | An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. An unauthenticated attacker can reboot the device causing a Denial of Service, via a hidden reboot command to '/media/?action=cmd'. | |
| Modificada | Alta (8.8) | 0.51% | — | Insma Wifi Mini SPY 1080p HD Security IP Camera Firmware | 30/3/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B, via all fields to WebUI. | |
| Modificada | Media (4.3) | 0.50% | — | Cisco Video Surveillance 8000p IP Camera FirmwareCisco Video Surveillance 8020 IP Camera FirmwareCisco Video Surveillance 8030 IP Camera FirmwareCisco Video Surveillance 8070 IP Camera Firmware+4 | 13/1/2021 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. The vulnerability is due to missing checks when Cisco Discovery Protocol messages are processed. An attacker… | |
| Modificada | Alta (8.8) | 0.75% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 8/10/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute arbitrary code on an affected device or cause the device to reload. This vulnerability is due to missing checks when an IP camera processes a… | |
| Modificada | Media (6.5) | 0.45% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 8/10/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect processing of certain Cisco… | |
| Modificada | Alta (8.8) | 0.70% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 26/8/2020 | 17/6/2026 | Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabilities are due to missing checks when the IP cameras process… | |
| Modificada | Alta (8.8) | 0.95% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 26/8/2020 | 17/6/2026 | Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabilities are due to missing checks when the IP cameras process… | |
| Modificada | Media (6.5) | 0.57% | — | Cisco 8000p IP Camera FirmwareCisco 8020 IP Camera FirmwareCisco 8030 IP Camera FirmwareCisco 8070 IP Camera Firmware+4 | 26/8/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect processing of certain Cisco… | |
| Modificada | Alta (8.8) | 5.7% | — | Cisco Video Surveillance 8400 IP Camera FirmwareCisco Video Surveillance 8030 IP Camera FirmwareCisco Video Surveillance 8020 IP Camera FirmwareCisco Video Surveillance 8000p IP Camera Firmware+4 | 5/2/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP Camera. The vulnerability is due to missing checks when processing Cisco Discovery… | |
| Modificada | Media (6.1) | 3.1% | — | Sv3c H.264 POE IP Camera Firmware | 19/10/2018 | 17/6/2026 | The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpected endpoint. | |
| Modificada | Media (5.7) | 0.57% | — | Sv3c H.264 POE IP Camera Firmware | 19/10/2018 | 17/6/2026 | The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within the cookies of a session. If an attacker gained access to these session cookies, it would be possible to gain access to the username and password of the logged-in account. | |
| Modificada | Alta (7.5) | 1.2% | — | Sv3c H.264 POE IP Camera Firmware | 19/10/2018 | 17/6/2026 | An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including camera hardware, wireless network, and local area network information. | |
| Modificada | Media (5.4) | 0.55% | — | Sv3c H.264 POE IP Camera Firmware | 19/10/2018 | 17/6/2026 | The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input and is vulnerable to cross-site scripting attacks. If proper authorization was implemented, this vulnerability could be leveraged to perform actions on behalf of another user or the administrator. | |
| Modificada | Crítica (9.8) | 1.3% | — | Sv3c H.264 POE IP Camera Firmware | 19/10/2018 | 17/6/2026 | An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including all password sets set within the camera. This information can then be used to gain access to the web interface. | |
| Modificada | Crítica (9.8) | 3.3% | — | Sv3c H.264 POE IP Camera Firmware | 19/10/2018 | 17/6/2026 | SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow OS Command Injection. | |
| Modificada | Alta (8.8) | 1.4% | — | Sv3c H.264 POE IP Camera Firmware | 19/10/2018 | 17/6/2026 | SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow remote authenticated users to reset arbitrary accounts via a request to web/cgi-bin/hi3510/param.cgi. | |
| Modificada | Crítica (9.8) | 1.7% | — | Sv3c H.264 POE IP Camera Firmware | 19/10/2018 | 17/6/2026 | SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices have a Hard-coded Password. |