Vulnerability index

Browse CVEs

34 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-66176 There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker o… Ds K1t331 Firmware 3.7.80+ Fix from $1,9502026-01-13 MEDIUM 6.8 CVE-2025-66174 There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial… Ds 7104hghi F1 Firmware after 4.30.122_201107 Fix from $1,6002025-12-19 MEDIUM 6.2 CVE-2025-66173 There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial por… Ds 7104hghi F1 Firmware after 4.30.122_201107 Fix from $1,6002025-12-19 CRITICAL 9.8 CVE-2024-47485 There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate exec… Hikcentral Master 2.3.0+ Fix from $2,3002024-10-18 HIGH 8.8 CVE-2024-47487 There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL quer… Hikcentral Professional 2.6.1+ Fix from $1,9502024-10-18 MEDIUM 6.1 CVE-2024-47486 There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building … Hikcentral Master 2.3.0+ Fix from $1,6002024-10-18 HIGH 7.8 CVE-2023-33806 Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commands. Ds D5b86rb\/b Firmware Mitigation only Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-25063 Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that th… Hikcentral Professional after 2.5.1 Fix from $1,9502024-03-02 CRITICAL 9.8 CVE-2023-6895EPSS 89% A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability… Intercom Broadcast System 4.1.0+ Fix from $2,3002023-12-17 MEDIUM 6.5 CVE-2023-6894 A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been classified as problematic. This affects … Intercom Broadcast System 4.1.0+ Fix from $1,6002023-12-17 HIGH 7.5 CVE-2023-6893EPSS 70% A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. Affected by this issue… Intercom Broadcast System 4.1.0+ Fix from $1,9502023-12-17 HIGH 7.5 CVE-2023-28813 An attacker could exploit a vulnerability by sending crafted messages to computers installed with this plug-in to modify plug-in parameters, which co… Localservicecomponents after 1.0.0.78 Fix from $1,9502023-11-23 CRITICAL 9.8 CVE-2023-28812 There is a buffer overflow vulnerability in a web browser plug-in could allow an attacker to exploit the vulnerability by sending crafted messages to… Localservicecomponents after 1.0.0.78 Fix from $2,3002023-11-23 MEDIUM 6.5 CVE-2023-28811 There is a buffer overflow in the password recovery feature of Hikvision NVR/DVR models. If exploited, an attacker on the same local area network (LA… Nvr 216mh C\(d\) Firmware 4.1.60+ Fix from $1,6002023-11-23 HIGH 7.5 CVE-2023-28809 Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfull… Ds K1t320efwx Firmware No fix yet Fix from $1,9502023-06-15 CRITICAL 9.8 CVE-2023-28808 Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacke… Ds A71024 Firmware after 2.3.8-8 Fix from $2,3002023-04-11 CRITICAL 9.8 CVE-2022-28173 The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permission. The … Ds 3wf0ac 2nt Firmware 1.0.4 / 1.1.0+ Fix from $2,3002022-12-19 CRITICAL 9.8 CVE-2022-28171EPSS 50% The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validat… Ds A71024 Firmware after 2.3.8-6 Fix from $2,3002022-06-27 MEDIUM 6.1 CVE-2022-28172 The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validat… Ds A71024 Firmware after 2.3.8-6 Fix from $1,6002022-06-27 CRITICAL 9.8 CVE-2021-36260 KEVEPSS 100% A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vul… Ds 2cd2026g2 Iu\/sl Firmware Mitigation only Fix from $2,3002021-09-22 MEDIUM 5.3 CVE-2020-7057 Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login att… Ds 7204hghi F1 Firmware No fix yet Fix from $1,6002020-01-14 CRITICAL 9.8 CVE-2013-4976EPSS 36% Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials Ds 2cd7153 E Firmware No fix yet Fix from $2,3002019-12-27 HIGH 8.8 CVE-2013-4975EPSS 12% Hikvision DS-2CD7153-E IP Camera has Privilege Escalation Ds 2cd7153 E Firmware No fix yet Fix from $1,9502019-12-27 CRITICAL 9.8 CVE-2018-6414 A buffer overflow vulnerability in the web server of some Hikvision IP Cameras allows an attacker to send a specially crafted message to affected dev… Ip Cameras Mitigation only Fix from $2,3002018-08-13 HIGH 7.5 CVE-2018-6413 There is a buffer overflow in the Hikvision Camera DS-2CD9111-S of V4.1.2 build 160203 and before, and this vulnerability allows remote attackers to … Ds 2cd9111 S Firmware after 4.1.2 Fix from $1,9502018-04-18 MEDIUM 6.5 CVE-2017-14953 HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger association with an arbitrary access … Ds 2cd2432f Iw Firmware 5.4.5+ Fix from $1,6002017-12-01 HIGH 7.8 CVE-2017-13774 Hikvision iVMS-4200 devices before v2.6.2.7 allow local users to generate password-recovery codes via unspecified vectors. Ivms 4200 after 2.6.2.6 Fix from $1,9502017-08-30 CRITICAL 9.8 CVE-2017-7921 KEVEPSS 100% An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5… Ds 2cd2032 I Firmware Patch available Fix from $2,3002017-05-06 HIGH 8.8 CVE-2017-7923 A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Ser… Ds 2cd2032 I Firmware Patch available Fix from $1,9502017-05-06 MEDIUM 6.5 CVE-2015-4407 Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service… Ds 76xxx Series Firmware after 3.3.4 Fix from $1,6002017-03-13