CVE tracker

Every published vulnerability we hold that names a video product, most recent first. 1279 in total; the 250 most recent are listed. Per-product history is on CameraRisk.

CVEPublishedSeverityEPSSStatusSummary
CVE-2026-75619 2026-08-19 medium 6.9 0.2% Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on…
CVE-2026-75618 2026-08-19 high 7.1 0.2% Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local…
CVE-2026-15316 2026-08-18 high 7.1 0.2% An improper input validation vulnerability in the configuration service for processing encrypted credential data has…
CVE-2026-15315 2026-08-18 high 8.7 0.3% Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification…
CVE-2026-13545 2026-06-29 high 7.4 5.5% A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi…
CVE-2026-12760 2026-06-24 high 7.1 0.4% A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to…
CVE-2026-12174 2026-06-13 high 7.4 0.6% A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the…
CVE-2026-6250 2026-06-11 high 7.0 0.5% An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of…
CVE-2026-11497 2026-06-08 medium 5.5 0.4% A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality…
CVE-2026-8714 2026-06-05 high 7.1 0.2% A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper…
CVE-2026-1871 2026-06-02 high 7.1 0.3% TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper…
CVE-2026-35718 2026-06-02 medium 6.5 0.7% A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a…
CVE-2026-35716 2026-06-02 medium 6.3 0.3% A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows…
CVE-2026-30652 2026-06-02 high 8.8 0.5% A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek…
CVE-2026-30650 2026-06-02 high 8.8 0.6% A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the…
CVE-2026-30649 2026-06-02 high 7.3 0.4% Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via…
CVE-2026-35717 2026-06-02 medium 6.3 0.3% A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows…
CVE-2024-47272 2026-05-27 low 2.7 0.2% Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575…
CVE-2024-47271 2026-05-27 medium 4.9 0.3% Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before…
CVE-2024-47270 2026-05-27 low 2.7 0.2% Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station…
CVE-2024-47269 2026-05-27 medium 4.9 0.2% Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance…
CVE-2024-47268 2026-05-27 medium 4.9 0.3% Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and…
CVE-2024-47267 2026-05-27 low 2.7 0.3% Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull…
CVE-2026-1185 2026-05-12 high 8.8 0.2% A configuration file on the local file system had improper input validation which could allow code execution and…
CVE-2026-0804 2026-05-12 high 7.3 0.1% An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to…
CVE-2026-0802 2026-05-12 high 7.3 0.4% An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead…
CVE-2026-0541 2026-05-12 high 7.3 0.1% ACAP applications can gain elevated privileges due to improper input validation during the installation process,…
CVE-2026-36983 2026-05-11 high 7.3 1.2% D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The…
CVE-2026-8260 2026-05-11 high 7.4 1.0% A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of…
CVE-2026-7372 2026-05-04 critical 9.0 0.5% A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A…
CVE-2026-7371 2026-05-04 medium 6.1 0.2% Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of…
CVE-2026-7161 2026-05-04 critical 9.3 0.2% An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device…
CVE-2026-42370 2026-05-04 critical 9.8 0.5% A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A…
CVE-2026-42368 2026-05-04 critical 9.9 0.4% A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A…
CVE-2026-42367 2026-05-04 medium 6.5 0.3% A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211…
CVE-2026-42366 2026-05-04 medium 6.1 0.2% Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of…
CVE-2026-42365 2026-05-04 high 7.5 0.3% A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A…
CVE-2026-42364 2026-05-04 high 8.8 1.7% An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A…
CVE-2024-54013 2026-04-28 high 8.7 0.2% Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server…
CVE-2024-54012 2026-04-28 high 8.5 0.3% Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate…
CVE-2024-54011 2026-04-28 medium 5.3 0.2% Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data…
CVE-2026-34124 2026-04-02 high 7.1 0.3% A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing…
CVE-2026-34122 2026-04-02 high 7.1 0.3% A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling…
CVE-2026-34121 2026-04-02 high 8.7 0.4% An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS…
CVE-2026-34120 2026-04-02 high 7.1 0.2% A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing…
CVE-2026-34119 2026-04-02 high 7.1 0.2% A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when…
CVE-2026-34118 2026-04-02 high 7.1 0.4% A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST…
CVE-2026-5312 2026-04-01 medium 5.5 0.5% A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-5311 2026-04-01 medium 5.5 1.0% A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321,…
CVE-2026-5215 2026-03-31 low 2.1 0.8% A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-5214 2026-03-31 high 7.4 0.7% A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-5213 2026-03-31 high 7.4 0.7% A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-5212 2026-03-31 high 7.4 0.7% A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-5211 2026-03-31 high 7.4 0.7% A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323,…
CVE-2026-33470 2026-03-26 medium 4.3 0.3% Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, a…
CVE-2026-33469 2026-03-26 medium 6.5 0.2% Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an…
CVE-2026-33126 2026-03-20 medium 4.3 0.2% Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3,…
CVE-2026-22898 2026-03-20 critical 9.3 0.7% A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers…
CVE-2026-33125 2026-03-20 high 8.1 0.2% Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and…
CVE-2026-33124 2026-03-20 high 8.6 0.2% Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to…
CVE-2026-4214 2026-03-16 high 7.4 0.8% A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323,…
CVE-2026-4213 2026-03-16 high 7.4 0.7% A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-4212 2026-03-16 high 7.4 0.8% A security vulnerability has been detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW,…
CVE-2026-4211 2026-03-16 high 7.4 0.8% A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-4210 2026-03-16 low 2.1 3.9% A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321,…
CVE-2026-4209 2026-03-16 low 2.1 4.5% A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-4207 2026-03-16 low 2.1 4.1% A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-4206 2026-03-16 low 2.1 3.6% A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-4205 2026-03-16 low 2.1 3.8% A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-4204 2026-03-16 low 2.1 3.7% A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323,…
CVE-2026-4203 2026-03-16 low 2.1 4.2% A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-4197 2026-03-16 low 2.1 18.4% A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-4196 2026-03-16 low 2.1 4.1% A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2026-4195 2026-03-16 low 2.1 3.8% A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323,…
CVE-2026-4194 2026-03-16 medium 5.5 1.2% A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,…
CVE-2024-14025 2026-03-11 low 0.1 0.1% An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who…
CVE-2024-14024 2026-03-11 low 0.1 0.1% An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local…
CVE-2025-59787 2026-03-04 medium 5.3 0.2% 2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving…
CVE-2025-59786 2026-03-04 medium 6.0 0.3% 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to…
CVE-2025-59785 2026-03-04 medium 5.3 0.2% Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password…
CVE-2025-59784 2026-03-04 medium 6.9 0.3% 2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be…
CVE-2025-59783 2026-03-04 high 8.8 0.9% API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation…
CVE-2025-1789 2026-02-24 medium 5.8 0.1% Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this…
CVE-2025-1787 2026-02-24 medium 5.8 0.1% Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin…
CVE-2026-27470 2026-02-21 high 8.8 0.5% ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and…
CVE-2019-25436 2026-02-20 medium 5.1 0.2% Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users…
CVE-2019-25435 2026-02-20 high 8.4 0.3% Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function…
CVE-2019-25355 2026-02-18 high 8.7 1.2% gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by…
CVE-2025-65791 2026-02-18 critical 9.8 1.6% ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user…
CVE-2025-9293 2026-02-13 high 7.7 0.2% A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated…
CVE-2025-9292 2026-02-13 low 2.0 0.3% A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed…
CVE-2026-0653 2026-02-10 high 7.2 0.4% On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by…
CVE-2026-0652 2026-02-10 high 8.7 21.6% On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters…
CVE-2026-0651 2026-02-10 medium 6.9 0.3% A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP…
CVE-2025-12063 2026-02-10 medium 5.7 0.2% An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having…
CVE-2025-13064 2026-02-10 medium 4.5 0.2% A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script…
CVE-2025-12757 2026-02-10 medium 4.6 0.3% An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are…
CVE-2025-11547 2026-02-10 high 7.8 0.1% AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin…
CVE-2025-11142 2026-02-10 high 8.8 0.5% The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code…
CVE-2026-2260 2026-02-10 high 7.3 5.0% A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file…
CVE-2026-2227 2026-02-09 low 2.0 5.9% A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file…
CVE-2026-2218 2026-02-09 low 2.1 3.8% A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file…
CVE-2026-25643 2026-02-06 critical 9.1 2.9% Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a…
CVE-2026-1457 2026-01-29 high 8.5 6.9% An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory…
CVE-2026-1532 2026-01-28 low 1.9 0.7% A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file…
CVE-2026-1315 2026-01-27 high 7.1 0.6% By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core…
CVE-2026-0919 2026-01-27 high 7.1 0.6% The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively…
CVE-2026-0918 2026-01-27 high 7.1 0.7% The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an…
CVE-2026-1419 2026-01-26 low 2.0 15.4% A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode…
CVE-2025-66176 2026-01-13 high 8.8 0.5% There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control…
CVE-2025-66052 2026-01-09 high 8.6 1.4% Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by…
CVE-2025-66051 2026-01-09 medium 6.9 0.7% Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated…
CVE-2025-66050 2026-01-09 critical 9.3 0.3% Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as…
CVE-2025-66049 2026-01-09 high 8.7 0.4% Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera…
CVE-2024-58337 2025-12-30 high 8.7 0.2% Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges…
CVE-2024-58336 2025-12-30 high 8.7 0.4% Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video…
CVE-2025-15245 2025-12-30 low 2.0 0.6% A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware…
CVE-2025-8075 2025-12-26 medium 5.8 0.2% Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and…
CVE-2025-52601 2025-12-26 medium 6.3 0.1% Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and…
CVE-2025-52600 2025-12-26 medium 5.2 0.4% Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and…
CVE-2025-52599 2025-12-26 medium 6.3 0.2% Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and…
CVE-2025-52598 2025-12-26 medium 6.3 0.2% Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and…
CVE-2018-25139 2025-12-24 high 8.7 0.5% FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live…
CVE-2018-25138 2025-12-24 critical 9.3 0.6% FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal…
CVE-2025-65857 2025-12-22 high 7.5 0.4% An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The…
CVE-2025-65856 2025-12-22 critical 9.8 0.8% Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF…
CVE-2025-8065 2025-12-20 high 8.7 0.5% A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS…
CVE-2025-14300 2025-12-20 high 8.7 0.4% The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper…
CVE-2025-14299 2025-12-20 high 7.1 0.2% The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer…
CVE-2025-66174 2025-12-19 medium 6.8 0.4% There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of…
CVE-2025-66173 2025-12-19 medium 6.2 0.2% There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of…
CVE-2025-65297 2025-12-10 high 7.5 0.2% Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect…
CVE-2025-65296 2025-12-10 medium 6.5 0.3% NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in…
CVE-2025-65295 2025-12-10 high 8.1 0.2% Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and…
CVE-2025-65294 2025-12-10 critical 9.8 1.0% Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented…
CVE-2025-65293 2025-12-10 medium 6.6 1.1% Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with…
CVE-2025-65292 2025-12-10 high 7.3 0.8% Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3…
CVE-2025-65291 2025-12-10 high 7.4 0.2% Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server…
CVE-2025-65290 2025-12-10 high 7.4 0.2% Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server…
CVE-2025-14225 2025-12-08 low 2.1 8.9% A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of…
CVE-2025-57202 2025-12-03 medium 6.1 0.5% A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104…
CVE-2025-57201 2025-12-03 high 8.8 17.2% AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command…
CVE-2025-57199 2025-12-03 high 8.8 3.3% AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command…
CVE-2025-57198 2025-12-03 high 8.8 2.8% AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command…
CVE-2025-57200 2025-12-03 medium 6.5 2.4% AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command…
CVE-2025-65407 2025-12-01 medium 6.5 0.3% A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows…
CVE-2025-65408 2025-12-01 medium 6.5 0.3% A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming…
CVE-2025-65406 2025-12-01 medium 6.5 0.3% A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02…
CVE-2025-65405 2025-12-01 medium 6.5 0.3% A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows…
CVE-2025-65404 2025-12-01 medium 6.5 0.3% A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a…
CVE-2025-63408 2025-11-18 high 7.8 0.4% Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local…
CVE-2025-8108 2025-11-11 medium 6.7 0.1% An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to…
CVE-2025-6779 2025-11-11 medium 6.7 1.1% An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to…
CVE-2025-6298 2025-11-11 medium 6.7 0.1% ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege…
CVE-2025-5718 2025-11-11 medium 6.8 0.4% The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only…
CVE-2025-5454 2025-11-11 medium 6.7 0.2% An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to…
CVE-2025-5452 2025-11-11 medium 6.6 0.3% A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP…
CVE-2025-4645 2025-11-11 medium 6.7 0.1% An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This…
CVE-2025-56802 2025-10-21 medium 5.1 0.1% The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration…
CVE-2025-56801 2025-10-21 medium 5.1 0.1% The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB…
CVE-2025-56800 2025-10-21 medium 5.1 0.2% Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application…
CVE-2025-56799 2025-10-21 medium 6.5 1.2% Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing…
CVE-2024-56804 2025-10-03 medium 5.3 0.4% An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account,…
CVE-2025-60787 2025-10-03 high 7.2 18.5% MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as…
CVE-2025-10779 2025-09-22 high 7.4 0.9% A vulnerability was found in D-Link DCS-935L up to 1.13.01. The impacted element is the function sub_402280 of the file…
CVE-2025-50944 2025-09-15 high 8.8 0.3% An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes…
CVE-2025-46408 2025-09-15 critical 9.8 0.7% An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and…
CVE-2025-10227 2025-09-10 medium 5.1 0.1% Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before…
CVE-2025-10226 2025-09-10 critical 9.3 0.6% Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk)…
CVE-2025-10225 2025-09-10 high 8.7 0.4% Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module…
CVE-2025-10224 2025-09-10 medium 5.3 0.3% Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier…
CVE-2025-10223 2025-09-10 medium 5.3 0.3% Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on…
CVE-2025-10222 2025-09-10 medium 4.8 0.1% Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft…
CVE-2025-10221 2025-09-10 medium 6.7 0.1% Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet…
CVE-2025-10220 2025-09-10 critical 9.3 0.7% Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS…
CVE-2025-56267 2025-09-08 critical 9.8 0.7% A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute…
CVE-2025-56266 2025-09-08 critical 9.8 2.9% A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via…
CVE-2025-9828 2025-09-02 low 2.9 0.3% A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the…
CVE-2024-46484 2025-08-29 critical 9.8 1.1% TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the…
CVE-2025-52856 2025-08-29 critical 9.3 0.6% An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then…
CVE-2025-55582 2025-08-27 medium 6.6 0.2% D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly…
CVE-2025-55581 2025-08-22 high 7.3 0.2% D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the…
CVE-2025-55637 2025-08-22 critical 9.8 1.7% Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a…
CVE-2025-55634 2025-08-22 high 7.5 0.5% Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime -…
CVE-2025-55630 2025-08-22 high 7.3 0.3% A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell…
CVE-2025-55625 2025-08-22 medium 6.3 0.2% An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via…
CVE-2025-55624 2025-08-22 medium 5.3 0.3% An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal…
CVE-2025-55623 2025-08-22 medium 5.4 0.3% An issue in the lock screen component of Reolink v4.54.0.4.20250526 allows attackers to bypass authentication via using…
CVE-2025-55622 2025-08-22 medium 6.5 0.3% Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity…
CVE-2025-55621 2025-08-22 medium 6.5 0.2% An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to…
CVE-2025-55620 2025-08-22 medium 6.1 0.2% A cross-site scripting (XSS) vulnerability in the valuateJavascript() function of Reolink v4.54.0.4.20250526 allows…
CVE-2025-55619 2025-08-22 critical 9.8 0.4% Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker…
CVE-2025-3892 2025-08-12 medium 6.7 0.1% ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This…
CVE-2025-30027 2025-08-12 medium 6.7 0.2% An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This…
CVE-2025-7622 2025-08-12 medium 5.1 0.2% During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an…
CVE-2025-8155 2025-07-25 low 2.0 15.1% A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this…
CVE-2025-52363 2025-07-14 medium 6.8 0.2% Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An…
CVE-2025-30026 2025-07-11 medium 5.3 0.6% The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally…
CVE-2025-30025 2025-07-11 medium 4.8 0.2% The communication protocol used between the server process and the service control had a flaw that could lead to a…
CVE-2025-30024 2025-07-11 medium 6.8 0.3% The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the…
CVE-2025-30023 2025-07-11 critical 9.0 0.5% The communication protocol used between client and server had a flaw that could lead to an authenticated user…
CVE-2025-52364 2025-07-09 high 7.5 0.5% Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default…
CVE-2025-6932 2025-06-30 low 2.9 0.9% A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the…
CVE-2025-6931 2025-06-30 low 2.9 1.7% A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this…
CVE-2025-34036 2025-06-24 critical 10.0 26.9% An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service…
CVE-2025-6266 2025-06-19 low 2.1 0.4% A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown…
CVE-2025-5763 2025-06-06 low 2.0 4.6% A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this…
CVE-2025-5695 2025-06-05 low 2.0 7.0% A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. This impacts the function…
CVE-2025-5573 2025-06-04 medium 5.3 12.0% A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by this issue is the…
CVE-2025-5572 2025-06-04 high 8.7 4.8% A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability…
CVE-2025-5571 2025-06-04 medium 5.3 11.9% A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function…
CVE-2025-0358 2025-06-02 high 8.8 0.2% During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX…
CVE-2025-0324 2025-06-02 high 8.8 0.4% The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain…
CVE-2024-13966 2025-05-27 medium 6.9 0.4% ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged…
CVE-2025-5215 2025-05-27 high 8.7 1.4% A vulnerability classified as critical has been found in D-Link DCS-5020L 1.01_B2. This affects the function…
CVE-2025-5127 2025-05-24 low 2.0 0.8% A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the…
CVE-2025-5126 2025-05-24 high 7.4 4.7% A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of…
CVE-2025-4843 2025-05-18 high 8.7 1.2% A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. This affects the function…
CVE-2025-4842 2025-05-17 high 8.7 1.2% A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. This vulnerability affects the…
CVE-2025-4841 2025-05-17 high 8.7 1.2% A vulnerability was found in D-Link DCS-932L 2.18.01 and classified as critical. Affected by this issue is the function…
CVE-2025-45746 2025-05-13 critical 9.8 0.4% In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to…
CVE-2025-1056 2025-04-23 medium 6.5 0.2% Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the…
CVE-2025-0926 2025-04-23 high 7.3 0.2% Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to…
CVE-2025-0361 2025-04-08 medium 5.3 0.3% During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX…
CVE-2024-47261 2025-04-08 medium 4.3 0.4% 51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have…
CVE-2025-1316 2025-03-05 critical 9.3 74.5% exploited Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve…
CVE-2025-0360 2025-03-04 high 7.8 0.1% During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX…
CVE-2025-0359 2025-03-04 medium 5.5 0.1% During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP…
CVE-2024-47259 2025-03-04 high 7.1 0.5% Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a…
CVE-2024-7696 2025-01-07 medium 6.3 0.2% Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated…
CVE-2024-37606 2024-12-17 medium 6.5 0.5% A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service…
CVE-2024-12553 2024-12-13 medium 6.5 0.6% GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote…
CVE-2023-52944 2024-12-04 medium 4.3 0.4% Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before…
CVE-2023-52943 2024-12-04 medium 4.3 0.4% Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before…
CVE-2024-8160 2024-11-26 low 2.7 0.6% Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a…
CVE-2024-6249 2024-11-22 high 8.8 1.3% Wyze Cam v3 TCP Traffic Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability…
CVE-2024-6248 2024-11-22 high 7.5 1.2% Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows…
CVE-2024-6247 2024-11-22 medium 6.8 2.2% Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically…
CVE-2024-6246 2024-11-22 high 8.8 1.0% Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability…
CVE-2024-11120 2024-11-15 critical 9.8 28.4% exploited Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit…
CVE-2024-11049 2024-11-10 medium 6.3 0.4% A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of…
CVE-2024-47255 2024-11-05 high 7.8 0.1% In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which…
CVE-2024-47254 2024-11-05 high 7.2 0.4% In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability…
CVE-2024-47253 2024-11-05 high 7.2 1.0% In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with…
CVE-2024-47487 2024-10-18 high 7.2 0.5% There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user…
CVE-2024-47486 2024-10-18 low 2.1 0.3% There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts…
CVE-2024-47485 2024-10-18 medium 5.5 0.6% There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build…
CVE-2023-31493 2024-10-15 medium 6.6 0.5% RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in…
CVE-2024-48168 2024-10-14 critical 9.8 1.0% A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing…
CVE-2023-51157 2024-09-25 medium 5.4 0.5% Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and…