Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2024-39950
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate…
Nvr4104 4ks2\/l Firmware
4.003.0000000.1.r.240515+
HIGH 7.5
CVE-2024-39948
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing th…
Nvr4104 4ks2\/l Firmware
4.003.0000000.1.r.240515+
HIGH 7.5
CVE-2024-39949
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing th…
Nvr4104 4ks2\/l Firmware
4.003.0000000.1.r.240515+
MEDIUM 6.5
CVE-2024-39947
A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted…
Nvr4104 4ks2\/l Firmware
4.003.0000000.1.r.240515+
HIGH 7.2
CVE-2024-39946
A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted…
Nvr4104 4ks2\/l Firmware
4.003.0000000.1.r.240515+
HIGH 7.5
CVE-2024-39944
A vulnerability has been found in Dahua products.Attackers
can send carefully crafted data packets to the interface with vulnerabilities,
causing the…
Nvr4104 4ks2\/l Firmware
4.003.0000000.1.r.240515+
CRITICAL 9.8
CVE-2023-3836EPSS 74%
A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /…
Smart Parking Management
after 20230713
MEDIUM 5.3
CVE-2022-30564
Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the …
Ipc Hf71242f Z X Firmware
2.800.0000000.4.r.210708 / 2.812.0000032.2.r.220804+
HIGH 7.5
CVE-2022-45423
Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials b…
Dss Express
Patch available
HIGH 7.5
CVE-2022-45425
Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting t…
Dss Express
Patch available
HIGH 7.5
CVE-2022-45429
Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating l…
Dss Express
Patch available
HIGH 7.5
CVE-2022-45431
Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy…
Dhi Dss7016d S2 Firmware
Patch available
HIGH 7.2
CVE-2022-45427
Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a spe…
Dss Express
Patch available
MEDIUM 6.5
CVE-2022-45426
Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of ordinary users, by sending a s…
Dss Express
Patch available
MEDIUM 5.9
CVE-2022-45434
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall ac…
Dhi Dss7016d S2 Firmware
Patch available
MEDIUM 5.3
CVE-2022-45424
Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending …
Dss Express
Patch available
MEDIUM 5.3
CVE-2022-45432
Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sendi…
Dhi Dss7016d S2 Firmware
Patch available
HIGH 7.4
CVE-2022-30560
When an attacker obtaining the administrative account and password, or through a man-in-the-middle attack, the attacker could send a specified crafte…
Ipc Hdbw2431e S S2 Firmware
2022-04+
HIGH 7.4
CVE-2022-30563
When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he can log in to the device by r…
Ipc Hdbw2431e S S2 Firmware
2022-04+
MEDIUM 5.9
CVE-2022-30561
When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker could log in to the device by rep…
Ipc Hdbw2431e S S2 Firmware
2022-04+
CRITICAL 9.8
CVE-2021-33046
Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deploy…
Ipc Hx1xxx Firmware
after 2021-7
CRITICAL 9.8
CVE-2021-33044 KEVEPSS 100%
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authenti…
Ipc Hum7xxx Firmware
2.800.0000000.29.r.210630 / 2.812.0000007.0.r.210706+
CRITICAL 9.8
CVE-2021-33045 KEVEPSS 100%
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authenti…
Ipc Hum7xxx Firmware
2.800.0000000.29.r.210630 / 2.820.0000000.5.r.210705+
CRITICAL 9.8
CVE-2020-9502
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use …
Sd6al Firmware
2019-12+
MEDIUM 5.5
CVE-2020-9501
Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways. Cloud Key is used to authenticate the connection between …
Web P2p
2020-04+
HIGH 8.1
CVE-2019-9682
Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of …
Sd6al Firmware
2019-12+
HIGH 7.2
CVE-2020-9499
Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test co…
Sd6al Firmware
2019-12+
HIGH 8.8
CVE-2019-9679
Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected product…
Ipc Hdw1x2x Firmware
2019-08-18+
HIGH 7.5
CVE-2019-9678
Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crashed by constructing a maliciou…
Ipc Hdw1x2x Firmware
2019-08-18+
MEDIUM 5.3
CVE-2019-9680
Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of the device by constructing m…
Ipc Hdw1x2x Firmware
2019-08-18+