CVE tracker
Every published vulnerability we hold that names a video product, most recent first. 1279 in total; the 250 most recent are listed. Per-product history is on CameraRisk.
| CVE | Published | Severity | EPSS | Status | Summary |
|---|---|---|---|---|---|
| CVE-2026-75619 | 2026-08-19 | medium 6.9 | 0.2% | Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on… | |
| CVE-2026-75618 | 2026-08-19 | high 7.1 | 0.2% | Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local… | |
| CVE-2026-15316 | 2026-08-18 | high 7.1 | 0.2% | An improper input validation vulnerability in the configuration service for processing encrypted credential data has… | |
| CVE-2026-15315 | 2026-08-18 | high 8.7 | 0.3% | Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification… | |
| CVE-2026-13545 | 2026-06-29 | high 7.4 | 5.5% | A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi… | |
| CVE-2026-12760 | 2026-06-24 | high 7.1 | 0.4% | A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to… | |
| CVE-2026-12174 | 2026-06-13 | high 7.4 | 0.6% | A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the… | |
| CVE-2026-6250 | 2026-06-11 | high 7.0 | 0.5% | An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of… | |
| CVE-2026-11497 | 2026-06-08 | medium 5.5 | 0.4% | A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality… | |
| CVE-2026-8714 | 2026-06-05 | high 7.1 | 0.2% | A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper… | |
| CVE-2026-1871 | 2026-06-02 | high 7.1 | 0.3% | TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper… | |
| CVE-2026-35718 | 2026-06-02 | medium 6.5 | 0.7% | A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a… | |
| CVE-2026-35716 | 2026-06-02 | medium 6.3 | 0.3% | A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows… | |
| CVE-2026-30652 | 2026-06-02 | high 8.8 | 0.5% | A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek… | |
| CVE-2026-30650 | 2026-06-02 | high 8.8 | 0.6% | A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the… | |
| CVE-2026-30649 | 2026-06-02 | high 7.3 | 0.4% | Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via… | |
| CVE-2026-35717 | 2026-06-02 | medium 6.3 | 0.3% | A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows… | |
| CVE-2024-47272 | 2026-05-27 | low 2.7 | 0.2% | Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575… | |
| CVE-2024-47271 | 2026-05-27 | medium 4.9 | 0.3% | Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before… | |
| CVE-2024-47270 | 2026-05-27 | low 2.7 | 0.2% | Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station… | |
| CVE-2024-47269 | 2026-05-27 | medium 4.9 | 0.2% | Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance… | |
| CVE-2024-47268 | 2026-05-27 | medium 4.9 | 0.3% | Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and… | |
| CVE-2024-47267 | 2026-05-27 | low 2.7 | 0.3% | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull… | |
| CVE-2026-1185 | 2026-05-12 | high 8.8 | 0.2% | A configuration file on the local file system had improper input validation which could allow code execution and… | |
| CVE-2026-0804 | 2026-05-12 | high 7.3 | 0.1% | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to… | |
| CVE-2026-0802 | 2026-05-12 | high 7.3 | 0.4% | An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead… | |
| CVE-2026-0541 | 2026-05-12 | high 7.3 | 0.1% | ACAP applications can gain elevated privileges due to improper input validation during the installation process,… | |
| CVE-2026-36983 | 2026-05-11 | high 7.3 | 1.2% | D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The… | |
| CVE-2026-8260 | 2026-05-11 | high 7.4 | 1.0% | A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of… | |
| CVE-2026-7372 | 2026-05-04 | critical 9.0 | 0.5% | A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A… | |
| CVE-2026-7371 | 2026-05-04 | medium 6.1 | 0.2% | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of… | |
| CVE-2026-7161 | 2026-05-04 | critical 9.3 | 0.2% | An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device… | |
| CVE-2026-42370 | 2026-05-04 | critical 9.8 | 0.5% | A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A… | |
| CVE-2026-42368 | 2026-05-04 | critical 9.9 | 0.4% | A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A… | |
| CVE-2026-42367 | 2026-05-04 | medium 6.5 | 0.3% | A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211… | |
| CVE-2026-42366 | 2026-05-04 | medium 6.1 | 0.2% | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of… | |
| CVE-2026-42365 | 2026-05-04 | high 7.5 | 0.3% | A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A… | |
| CVE-2026-42364 | 2026-05-04 | high 8.8 | 1.7% | An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A… | |
| CVE-2024-54013 | 2026-04-28 | high 8.7 | 0.2% | Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server… | |
| CVE-2024-54012 | 2026-04-28 | high 8.5 | 0.3% | Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate… | |
| CVE-2024-54011 | 2026-04-28 | medium 5.3 | 0.2% | Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data… | |
| CVE-2026-34124 | 2026-04-02 | high 7.1 | 0.3% | A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing… | |
| CVE-2026-34122 | 2026-04-02 | high 7.1 | 0.3% | A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling… | |
| CVE-2026-34121 | 2026-04-02 | high 8.7 | 0.4% | An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS… | |
| CVE-2026-34120 | 2026-04-02 | high 7.1 | 0.2% | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing… | |
| CVE-2026-34119 | 2026-04-02 | high 7.1 | 0.2% | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when… | |
| CVE-2026-34118 | 2026-04-02 | high 7.1 | 0.4% | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST… | |
| CVE-2026-5312 | 2026-04-01 | medium 5.5 | 0.5% | A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-5311 | 2026-04-01 | medium 5.5 | 1.0% | A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321,… | |
| CVE-2026-5215 | 2026-03-31 | low 2.1 | 0.8% | A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-5214 | 2026-03-31 | high 7.4 | 0.7% | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-5213 | 2026-03-31 | high 7.4 | 0.7% | A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-5212 | 2026-03-31 | high 7.4 | 0.7% | A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-5211 | 2026-03-31 | high 7.4 | 0.7% | A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323,… | |
| CVE-2026-33470 | 2026-03-26 | medium 4.3 | 0.3% | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, a… | |
| CVE-2026-33469 | 2026-03-26 | medium 6.5 | 0.2% | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an… | |
| CVE-2026-33126 | 2026-03-20 | medium 4.3 | 0.2% | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3,… | |
| CVE-2026-22898 | 2026-03-20 | critical 9.3 | 0.7% | A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers… | |
| CVE-2026-33125 | 2026-03-20 | high 8.1 | 0.2% | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and… | |
| CVE-2026-33124 | 2026-03-20 | high 8.6 | 0.2% | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to… | |
| CVE-2026-4214 | 2026-03-16 | high 7.4 | 0.8% | A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323,… | |
| CVE-2026-4213 | 2026-03-16 | high 7.4 | 0.7% | A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-4212 | 2026-03-16 | high 7.4 | 0.8% | A security vulnerability has been detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW,… | |
| CVE-2026-4211 | 2026-03-16 | high 7.4 | 0.8% | A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-4210 | 2026-03-16 | low 2.1 | 3.9% | A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321,… | |
| CVE-2026-4209 | 2026-03-16 | low 2.1 | 4.5% | A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-4207 | 2026-03-16 | low 2.1 | 4.1% | A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-4206 | 2026-03-16 | low 2.1 | 3.6% | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-4205 | 2026-03-16 | low 2.1 | 3.8% | A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-4204 | 2026-03-16 | low 2.1 | 3.7% | A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323,… | |
| CVE-2026-4203 | 2026-03-16 | low 2.1 | 4.2% | A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-4197 | 2026-03-16 | low 2.1 | 18.4% | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-4196 | 2026-03-16 | low 2.1 | 4.1% | A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2026-4195 | 2026-03-16 | low 2.1 | 3.8% | A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323,… | |
| CVE-2026-4194 | 2026-03-16 | medium 5.5 | 1.2% | A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L,… | |
| CVE-2024-14025 | 2026-03-11 | low 0.1 | 0.1% | An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who… | |
| CVE-2024-14024 | 2026-03-11 | low 0.1 | 0.1% | An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local… | |
| CVE-2025-59787 | 2026-03-04 | medium 5.3 | 0.2% | 2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving… | |
| CVE-2025-59786 | 2026-03-04 | medium 6.0 | 0.3% | 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to… | |
| CVE-2025-59785 | 2026-03-04 | medium 5.3 | 0.2% | Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password… | |
| CVE-2025-59784 | 2026-03-04 | medium 6.9 | 0.3% | 2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be… | |
| CVE-2025-59783 | 2026-03-04 | high 8.8 | 0.9% | API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation… | |
| CVE-2025-1789 | 2026-02-24 | medium 5.8 | 0.1% | Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this… | |
| CVE-2025-1787 | 2026-02-24 | medium 5.8 | 0.1% | Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin… | |
| CVE-2026-27470 | 2026-02-21 | high 8.8 | 0.5% | ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and… | |
| CVE-2019-25436 | 2026-02-20 | medium 5.1 | 0.2% | Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users… | |
| CVE-2019-25435 | 2026-02-20 | high 8.4 | 0.3% | Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function… | |
| CVE-2019-25355 | 2026-02-18 | high 8.7 | 1.2% | gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by… | |
| CVE-2025-65791 | 2026-02-18 | critical 9.8 | 1.6% | ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user… | |
| CVE-2025-9293 | 2026-02-13 | high 7.7 | 0.2% | A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated… | |
| CVE-2025-9292 | 2026-02-13 | low 2.0 | 0.3% | A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed… | |
| CVE-2026-0653 | 2026-02-10 | high 7.2 | 0.4% | On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by… | |
| CVE-2026-0652 | 2026-02-10 | high 8.7 | 21.6% | On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters… | |
| CVE-2026-0651 | 2026-02-10 | medium 6.9 | 0.3% | A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP… | |
| CVE-2025-12063 | 2026-02-10 | medium 5.7 | 0.2% | An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having… | |
| CVE-2025-13064 | 2026-02-10 | medium 4.5 | 0.2% | A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script… | |
| CVE-2025-12757 | 2026-02-10 | medium 4.6 | 0.3% | An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are… | |
| CVE-2025-11547 | 2026-02-10 | high 7.8 | 0.1% | AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin… | |
| CVE-2025-11142 | 2026-02-10 | high 8.8 | 0.5% | The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code… | |
| CVE-2026-2260 | 2026-02-10 | high 7.3 | 5.0% | A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file… | |
| CVE-2026-2227 | 2026-02-09 | low 2.0 | 5.9% | A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file… | |
| CVE-2026-2218 | 2026-02-09 | low 2.1 | 3.8% | A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file… | |
| CVE-2026-25643 | 2026-02-06 | critical 9.1 | 2.9% | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a… | |
| CVE-2026-1457 | 2026-01-29 | high 8.5 | 6.9% | An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory… | |
| CVE-2026-1532 | 2026-01-28 | low 1.9 | 0.7% | A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file… | |
| CVE-2026-1315 | 2026-01-27 | high 7.1 | 0.6% | By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core… | |
| CVE-2026-0919 | 2026-01-27 | high 7.1 | 0.6% | The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively… | |
| CVE-2026-0918 | 2026-01-27 | high 7.1 | 0.7% | The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an… | |
| CVE-2026-1419 | 2026-01-26 | low 2.0 | 15.4% | A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode… | |
| CVE-2025-66176 | 2026-01-13 | high 8.8 | 0.5% | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control… | |
| CVE-2025-66052 | 2026-01-09 | high 8.6 | 1.4% | Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by… | |
| CVE-2025-66051 | 2026-01-09 | medium 6.9 | 0.7% | Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated… | |
| CVE-2025-66050 | 2026-01-09 | critical 9.3 | 0.3% | Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as… | |
| CVE-2025-66049 | 2026-01-09 | high 8.7 | 0.4% | Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera… | |
| CVE-2024-58337 | 2025-12-30 | high 8.7 | 0.2% | Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges… | |
| CVE-2024-58336 | 2025-12-30 | high 8.7 | 0.4% | Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video… | |
| CVE-2025-15245 | 2025-12-30 | low 2.0 | 0.6% | A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware… | |
| CVE-2025-8075 | 2025-12-26 | medium 5.8 | 0.2% | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and… | |
| CVE-2025-52601 | 2025-12-26 | medium 6.3 | 0.1% | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and… | |
| CVE-2025-52600 | 2025-12-26 | medium 5.2 | 0.4% | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and… | |
| CVE-2025-52599 | 2025-12-26 | medium 6.3 | 0.2% | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and… | |
| CVE-2025-52598 | 2025-12-26 | medium 6.3 | 0.2% | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and… | |
| CVE-2018-25139 | 2025-12-24 | high 8.7 | 0.5% | FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live… | |
| CVE-2018-25138 | 2025-12-24 | critical 9.3 | 0.6% | FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal… | |
| CVE-2025-65857 | 2025-12-22 | high 7.5 | 0.4% | An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The… | |
| CVE-2025-65856 | 2025-12-22 | critical 9.8 | 0.8% | Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF… | |
| CVE-2025-8065 | 2025-12-20 | high 8.7 | 0.5% | A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS… | |
| CVE-2025-14300 | 2025-12-20 | high 8.7 | 0.4% | The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper… | |
| CVE-2025-14299 | 2025-12-20 | high 7.1 | 0.2% | The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer… | |
| CVE-2025-66174 | 2025-12-19 | medium 6.8 | 0.4% | There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of… | |
| CVE-2025-66173 | 2025-12-19 | medium 6.2 | 0.2% | There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of… | |
| CVE-2025-65297 | 2025-12-10 | high 7.5 | 0.2% | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect… | |
| CVE-2025-65296 | 2025-12-10 | medium 6.5 | 0.3% | NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in… | |
| CVE-2025-65295 | 2025-12-10 | high 8.1 | 0.2% | Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and… | |
| CVE-2025-65294 | 2025-12-10 | critical 9.8 | 1.0% | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented… | |
| CVE-2025-65293 | 2025-12-10 | medium 6.6 | 1.1% | Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with… | |
| CVE-2025-65292 | 2025-12-10 | high 7.3 | 0.8% | Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3… | |
| CVE-2025-65291 | 2025-12-10 | high 7.4 | 0.2% | Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server… | |
| CVE-2025-65290 | 2025-12-10 | high 7.4 | 0.2% | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server… | |
| CVE-2025-14225 | 2025-12-08 | low 2.1 | 8.9% | A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of… | |
| CVE-2025-57202 | 2025-12-03 | medium 6.1 | 0.5% | A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104… | |
| CVE-2025-57201 | 2025-12-03 | high 8.8 | 17.2% | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command… | |
| CVE-2025-57199 | 2025-12-03 | high 8.8 | 3.3% | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command… | |
| CVE-2025-57198 | 2025-12-03 | high 8.8 | 2.8% | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command… | |
| CVE-2025-57200 | 2025-12-03 | medium 6.5 | 2.4% | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command… | |
| CVE-2025-65407 | 2025-12-01 | medium 6.5 | 0.3% | A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows… | |
| CVE-2025-65408 | 2025-12-01 | medium 6.5 | 0.3% | A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming… | |
| CVE-2025-65406 | 2025-12-01 | medium 6.5 | 0.3% | A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02… | |
| CVE-2025-65405 | 2025-12-01 | medium 6.5 | 0.3% | A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows… | |
| CVE-2025-65404 | 2025-12-01 | medium 6.5 | 0.3% | A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a… | |
| CVE-2025-63408 | 2025-11-18 | high 7.8 | 0.4% | Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local… | |
| CVE-2025-8108 | 2025-11-11 | medium 6.7 | 0.1% | An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to… | |
| CVE-2025-6779 | 2025-11-11 | medium 6.7 | 1.1% | An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to… | |
| CVE-2025-6298 | 2025-11-11 | medium 6.7 | 0.1% | ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege… | |
| CVE-2025-5718 | 2025-11-11 | medium 6.8 | 0.4% | The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only… | |
| CVE-2025-5454 | 2025-11-11 | medium 6.7 | 0.2% | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to… | |
| CVE-2025-5452 | 2025-11-11 | medium 6.6 | 0.3% | A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP… | |
| CVE-2025-4645 | 2025-11-11 | medium 6.7 | 0.1% | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This… | |
| CVE-2025-56802 | 2025-10-21 | medium 5.1 | 0.1% | The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration… | |
| CVE-2025-56801 | 2025-10-21 | medium 5.1 | 0.1% | The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB… | |
| CVE-2025-56800 | 2025-10-21 | medium 5.1 | 0.2% | Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application… | |
| CVE-2025-56799 | 2025-10-21 | medium 6.5 | 1.2% | Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing… | |
| CVE-2024-56804 | 2025-10-03 | medium 5.3 | 0.4% | An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account,… | |
| CVE-2025-60787 | 2025-10-03 | high 7.2 | 18.5% | MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as… | |
| CVE-2025-10779 | 2025-09-22 | high 7.4 | 0.9% | A vulnerability was found in D-Link DCS-935L up to 1.13.01. The impacted element is the function sub_402280 of the file… | |
| CVE-2025-50944 | 2025-09-15 | high 8.8 | 0.3% | An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes… | |
| CVE-2025-46408 | 2025-09-15 | critical 9.8 | 0.7% | An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and… | |
| CVE-2025-10227 | 2025-09-10 | medium 5.1 | 0.1% | Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before… | |
| CVE-2025-10226 | 2025-09-10 | critical 9.3 | 0.6% | Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk)… | |
| CVE-2025-10225 | 2025-09-10 | high 8.7 | 0.4% | Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module… | |
| CVE-2025-10224 | 2025-09-10 | medium 5.3 | 0.3% | Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier… | |
| CVE-2025-10223 | 2025-09-10 | medium 5.3 | 0.3% | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on… | |
| CVE-2025-10222 | 2025-09-10 | medium 4.8 | 0.1% | Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft… | |
| CVE-2025-10221 | 2025-09-10 | medium 6.7 | 0.1% | Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet… | |
| CVE-2025-10220 | 2025-09-10 | critical 9.3 | 0.7% | Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS… | |
| CVE-2025-56267 | 2025-09-08 | critical 9.8 | 0.7% | A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute… | |
| CVE-2025-56266 | 2025-09-08 | critical 9.8 | 2.9% | A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via… | |
| CVE-2025-9828 | 2025-09-02 | low 2.9 | 0.3% | A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the… | |
| CVE-2024-46484 | 2025-08-29 | critical 9.8 | 1.1% | TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the… | |
| CVE-2025-52856 | 2025-08-29 | critical 9.3 | 0.6% | An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then… | |
| CVE-2025-55582 | 2025-08-27 | medium 6.6 | 0.2% | D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly… | |
| CVE-2025-55581 | 2025-08-22 | high 7.3 | 0.2% | D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the… | |
| CVE-2025-55637 | 2025-08-22 | critical 9.8 | 1.7% | Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a… | |
| CVE-2025-55634 | 2025-08-22 | high 7.5 | 0.5% | Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime -… | |
| CVE-2025-55630 | 2025-08-22 | high 7.3 | 0.3% | A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell… | |
| CVE-2025-55625 | 2025-08-22 | medium 6.3 | 0.2% | An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via… | |
| CVE-2025-55624 | 2025-08-22 | medium 5.3 | 0.3% | An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal… | |
| CVE-2025-55623 | 2025-08-22 | medium 5.4 | 0.3% | An issue in the lock screen component of Reolink v4.54.0.4.20250526 allows attackers to bypass authentication via using… | |
| CVE-2025-55622 | 2025-08-22 | medium 6.5 | 0.3% | Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity… | |
| CVE-2025-55621 | 2025-08-22 | medium 6.5 | 0.2% | An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to… | |
| CVE-2025-55620 | 2025-08-22 | medium 6.1 | 0.2% | A cross-site scripting (XSS) vulnerability in the valuateJavascript() function of Reolink v4.54.0.4.20250526 allows… | |
| CVE-2025-55619 | 2025-08-22 | critical 9.8 | 0.4% | Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker… | |
| CVE-2025-3892 | 2025-08-12 | medium 6.7 | 0.1% | ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This… | |
| CVE-2025-30027 | 2025-08-12 | medium 6.7 | 0.2% | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This… | |
| CVE-2025-7622 | 2025-08-12 | medium 5.1 | 0.2% | During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an… | |
| CVE-2025-8155 | 2025-07-25 | low 2.0 | 15.1% | A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this… | |
| CVE-2025-52363 | 2025-07-14 | medium 6.8 | 0.2% | Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An… | |
| CVE-2025-30026 | 2025-07-11 | medium 5.3 | 0.6% | The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally… | |
| CVE-2025-30025 | 2025-07-11 | medium 4.8 | 0.2% | The communication protocol used between the server process and the service control had a flaw that could lead to a… | |
| CVE-2025-30024 | 2025-07-11 | medium 6.8 | 0.3% | The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the… | |
| CVE-2025-30023 | 2025-07-11 | critical 9.0 | 0.5% | The communication protocol used between client and server had a flaw that could lead to an authenticated user… | |
| CVE-2025-52364 | 2025-07-09 | high 7.5 | 0.5% | Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default… | |
| CVE-2025-6932 | 2025-06-30 | low 2.9 | 0.9% | A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the… | |
| CVE-2025-6931 | 2025-06-30 | low 2.9 | 1.7% | A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this… | |
| CVE-2025-34036 | 2025-06-24 | critical 10.0 | 26.9% | An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service… | |
| CVE-2025-6266 | 2025-06-19 | low 2.1 | 0.4% | A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown… | |
| CVE-2025-5763 | 2025-06-06 | low 2.0 | 4.6% | A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this… | |
| CVE-2025-5695 | 2025-06-05 | low 2.0 | 7.0% | A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. This impacts the function… | |
| CVE-2025-5573 | 2025-06-04 | medium 5.3 | 12.0% | A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by this issue is the… | |
| CVE-2025-5572 | 2025-06-04 | high 8.7 | 4.8% | A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability… | |
| CVE-2025-5571 | 2025-06-04 | medium 5.3 | 11.9% | A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function… | |
| CVE-2025-0358 | 2025-06-02 | high 8.8 | 0.2% | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX… | |
| CVE-2025-0324 | 2025-06-02 | high 8.8 | 0.4% | The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain… | |
| CVE-2024-13966 | 2025-05-27 | medium 6.9 | 0.4% | ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged… | |
| CVE-2025-5215 | 2025-05-27 | high 8.7 | 1.4% | A vulnerability classified as critical has been found in D-Link DCS-5020L 1.01_B2. This affects the function… | |
| CVE-2025-5127 | 2025-05-24 | low 2.0 | 0.8% | A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the… | |
| CVE-2025-5126 | 2025-05-24 | high 7.4 | 4.7% | A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of… | |
| CVE-2025-4843 | 2025-05-18 | high 8.7 | 1.2% | A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. This affects the function… | |
| CVE-2025-4842 | 2025-05-17 | high 8.7 | 1.2% | A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. This vulnerability affects the… | |
| CVE-2025-4841 | 2025-05-17 | high 8.7 | 1.2% | A vulnerability was found in D-Link DCS-932L 2.18.01 and classified as critical. Affected by this issue is the function… | |
| CVE-2025-45746 | 2025-05-13 | critical 9.8 | 0.4% | In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to… | |
| CVE-2025-1056 | 2025-04-23 | medium 6.5 | 0.2% | Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the… | |
| CVE-2025-0926 | 2025-04-23 | high 7.3 | 0.2% | Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to… | |
| CVE-2025-0361 | 2025-04-08 | medium 5.3 | 0.3% | During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX… | |
| CVE-2024-47261 | 2025-04-08 | medium 4.3 | 0.4% | 51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have… | |
| CVE-2025-1316 | 2025-03-05 | critical 9.3 | 74.5% | exploited | Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve… |
| CVE-2025-0360 | 2025-03-04 | high 7.8 | 0.1% | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX… | |
| CVE-2025-0359 | 2025-03-04 | medium 5.5 | 0.1% | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP… | |
| CVE-2024-47259 | 2025-03-04 | high 7.1 | 0.5% | Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a… | |
| CVE-2024-7696 | 2025-01-07 | medium 6.3 | 0.2% | Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated… | |
| CVE-2024-37606 | 2024-12-17 | medium 6.5 | 0.5% | A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service… | |
| CVE-2024-12553 | 2024-12-13 | medium 6.5 | 0.6% | GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote… | |
| CVE-2023-52944 | 2024-12-04 | medium 4.3 | 0.4% | Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before… | |
| CVE-2023-52943 | 2024-12-04 | medium 4.3 | 0.4% | Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before… | |
| CVE-2024-8160 | 2024-11-26 | low 2.7 | 0.6% | Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a… | |
| CVE-2024-6249 | 2024-11-22 | high 8.8 | 1.3% | Wyze Cam v3 TCP Traffic Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability… | |
| CVE-2024-6248 | 2024-11-22 | high 7.5 | 1.2% | Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows… | |
| CVE-2024-6247 | 2024-11-22 | medium 6.8 | 2.2% | Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically… | |
| CVE-2024-6246 | 2024-11-22 | high 8.8 | 1.0% | Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability… | |
| CVE-2024-11120 | 2024-11-15 | critical 9.8 | 28.4% | exploited | Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit… |
| CVE-2024-11049 | 2024-11-10 | medium 6.3 | 0.4% | A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of… | |
| CVE-2024-47255 | 2024-11-05 | high 7.8 | 0.1% | In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which… | |
| CVE-2024-47254 | 2024-11-05 | high 7.2 | 0.4% | In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability… | |
| CVE-2024-47253 | 2024-11-05 | high 7.2 | 1.0% | In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with… | |
| CVE-2024-47487 | 2024-10-18 | high 7.2 | 0.5% | There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user… | |
| CVE-2024-47486 | 2024-10-18 | low 2.1 | 0.3% | There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts… | |
| CVE-2024-47485 | 2024-10-18 | medium 5.5 | 0.6% | There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build… | |
| CVE-2023-31493 | 2024-10-15 | medium 6.6 | 0.5% | RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in… | |
| CVE-2024-48168 | 2024-10-14 | critical 9.8 | 1.0% | A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing… | |
| CVE-2023-51157 | 2024-09-25 | medium 5.4 | 0.5% | Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and… |