Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2026-40434
Anviz CrossChex Standard
lacks source verification in the client/server channel, enabling TCP
packet injection by an attacker on the same network to…
Crosschex Standard
Mitigation only
HIGH 7.5
CVE-2026-40461
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug
settings (e.g., enabling SSH), allowing unauthorized state …
Cx7 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-35546
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted
archives to be accepted, enabling attackers to plant …
Cx7 Firmware
Mitigation only
HIGH 8.8
CVE-2026-40066
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unaut…
Cx7 Firmware
Mitigation only
HIGH 8.8
CVE-2026-35682
Anviz CX2 Lite is vulnerable to an authenticated command injection via a
filename parameter that enables arbitrary command execution (e.g.,
startin…
Cx2 Lite Firmware
Mitigation only
MEDIUM 5.3
CVE-2026-35061
Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be
retrieved without authentication, revealing sensitive operatio…
Cx7 Firmware
Mitigation only
HIGH 7.5
CVE-2026-32650
Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable
encryption, causing database credentials to be sent…
Crosschex Standard
Mitigation only
MEDIUM 6.5
CVE-2026-33569
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling
on‑path attackers to sniff credentials and session data, which can be
used…
Cx7 Firmware
Mitigation only
MEDIUM 5.3
CVE-2026-32648
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug
configuration details (e.g., SSH/RTTY status), assisting attack…
Cx7 Firmware
Mitigation only
MEDIUM 5.3
CVE-2026-33093
Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures
a photo with the front facing camera, exposing visual inform…
Cx7 Firmware
Mitigation only
HIGH 7.7
CVE-2026-32324
Anviz CX7 Firmware is
vulnerable because the application embeds reusable certificate/key
material, enabling decryption of MQTT traffic and potentia…
Cx7 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-12394
Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authen…
Management System
Mitigation only
CRITICAL 9.8
CVE-2019-12518EPSS 51%
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
Crosschex
No fix yet
CRITICAL 9.8
CVE-2019-12392
Anviz access control devices allow remote attackers to issue commands without a password.
Anviz Firmware
No fix yet
HIGH 7.5
CVE-2019-12388
Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/50…
Anviz Firmware
Mitigation only
HIGH 7.5
CVE-2019-12389
Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via …
Anviz Firmware
Mitigation only
HIGH 7.5
CVE-2019-12391
The Anviz Management System for access control has insufficient logging for device events such as door open requests.
Management System
No fix yet
HIGH 7.5
CVE-2019-12393
Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests.
Management System
Mitigation only
MEDIUM 5.3
CVE-2019-12390
Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this information without credential…
Anviz Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-11523
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully …
M3 Firmware
No fix yet