Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.25%—Auntvt Timo26/3/202617/6/2026
Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.
AplazadaCrítica (9.3)4.1%—Shenzhen TVT Digital Technology Nvms-9000AI24/11/202517/6/2026
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and an OS command injection flaw in its configuration services. The web/API interface accepts HTTP/XML requests authenticated with a fixed vendor credential string and…
AplazadaAlta (8.7)0.86%—Shenzhen TVT Digital Technology Nvms-9000AI24/11/202526/9/2026
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions prior to 1.3.4 contain an authentication bypass in the NVMS-9000 control protocol. By sending a single crafted TCP payload to an exposed NVMS-9000 control port, an unauthenticated remote attacker can…
ModificadaCrítica (10)31%—TVT Td-2108ts-cl FirmwareTVT Td-2108ts-cl-a FirmwareTVT Td-2116ts-cl FirmwareTVT Td-2104ts-hc Firmware+2624/6/202517/6/2026
An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 82. The web interface fails to sanitize input in the URI path passed to the language extraction functionality. When the server processes a…
AplazadaAlta (7.3)0.43%—Auntvt TimoAI10/2/202517/6/2026
An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file.
AnalizadaMedia (6.9)32%—Provision-isr Sh-4050a5-5l(mm) FirmwareTVT Avision Av108t FirmwareTVT Td-2104ts-cl FirmwareTVT Td-2108ts-hp Firmware1/8/202417/6/2026
A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be initiated remotely.…
AnalizadaCrítica (9.8)1.1%—Auntvt Timo20/2/202417/6/2026
An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component.
AnalizadaAlta (7.5)96%⚠ Explotación activaTVT Nvms-1000 Firmware30/12/201917/6/2026
TVT NVMS-1000 devices allow GET /.. Directory Traversal
ModificadaAlta (7.8)10%—TVT DVRTVT DVR Firmware2/11/201316/6/2026
Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI.
ModificadaAlta (7.2)0.35%—SAM Lantinga Splitvt22/2/200816/6/2026
misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.
ModificadaAlta (7.2)1.3%—SAM Lantinga SplitvtDebian Linux12/3/200116/6/2026
Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.
ModificadaAlta (7.2)1.2%—SAM Lantinga SplitvtDebian Linux12/3/200116/6/2026
Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.
ModificadaAlta (7.2)1.1%—SAM Lantinga Splitvt1/6/200016/6/2026
Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the screen locking function.
ModificadaAlta (7.2)0.41%—SAM Lantinga Splitvt1/12/199516/6/2026
Buffer overflow in Linux splitvt command gives root access to local users.