A camera reachable from the internet, running firmware with a flaw on this list, is how camera feeds end up public. The flaws here are already being exploited, so the gap between an unpatched box and a stranger watching it is the time it takes a scanner to find it.
For people who own cameras, a video recorder, or a NAS that stores footage: Hikvision, Dahua, Reolink, UniFi, QNAP, D-Link and the rest. The action is checking the firmware version on gear you already have. Looking for a camera someone else hid, start at the lens finder. Checking one specific host on your network, use the camera probe.
This list is curated and selective, never exhaustive. It is a hand-matched slice of the CISA catalogue covering cameras, recorders, NAS units and consumer network gear, so a device that does not appear here has not been given a clean bill of health: check the vendor advisory for your exact model and firmware build. The screen also knows nothing about your network and cannot tell you whether you run any of this hardware, whether it is reachable from outside, or whether it is already patched.
Every row is an entry in the CISA Known Exploited Vulnerabilities catalogue that we matched by hand to a camera, recorder, NAS unit or piece of consumer network gear. The matching is ours, so the coverage is only as wide as the product families we have written rules for, and a model missing from the list is a model we have not matched.
The due date is CISA's remediation deadline for US federal civilian agencies. It binds nobody else, and it stays the best public marker of how urgent CISA considered each bug.
EPSS is the chance of exploitation in the next 30 days. On a KEV entry it already happened, so a low score means targeted activity, never a reason to defer the patch.
Which product line has the most known-exploited bugs. Long bar, long break-in record. Red bar, ransomware crews used it. The NAS families sit high because a box holding recorded footage is worth encrypting.
Find the firmware version in the device's admin page and compare it against the vendor advisory linked from the CVE. Update it, then take the device off the public internet: no port forward, no UPnP hole, no vendor cloud relay you do not need. Change the admin password while you are in there, because most of these products shipped with a default one that is published.