Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-45746 In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NO… Zkbio Cvsecurity No fix yet Fix from $2,3002025-05-13 MEDIUM 5.4 CVE-2023-51157 Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via… Wdms No fix yet Fix from $1,6002024-09-25 CRITICAL 9.8 CVE-2024-36526 ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key. Zkbio Cvsecurity No fix yet Fix from $2,3002024-07-09 HIGH 8.1 CVE-2024-35433 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create… Zkbio Cvsecurity No fix yet Fix from $1,9502024-05-30 HIGH 7.5 CVE-2024-35431 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server.… Zkbio Cvsecurity No fix yet Fix from $1,9502024-05-30 HIGH 7.1 CVE-2024-35428 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server wh… Zkbio Cvsecurity No fix yet Fix from $1,9502024-05-30 MEDIUM 6.5 CVE-2024-35429 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord. Zkbio Cvsecurity No fix yet Fix from $1,6002024-05-30 HIGH 8.1 CVE-2024-35430 In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the app… Zkbio Cvsecurity No fix yet Fix from $1,9502024-05-30 MEDIUM 6.1 CVE-2024-35432 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Cross Site Scripting (XSS) via an Audio File. An authenticated user can injection malicious JavaScript… Zkbio Cvsecurity No fix yet Fix from $1,6002024-05-30 HIGH 7.5 CVE-2023-51142 An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information. Biotime No fix yet Fix from $1,9502024-04-11 MEDIUM 6.5 CVE-2023-51141 An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization compone… Biotime No fix yet Fix from $1,6002024-04-11 HIGH 7.5 CVE-2024-2318 A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of … Zkbio Media Mitigation only Fix from $1,9502024-03-08 CRITICAL 9.8 CVE-2024-22988 ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename … Zkbio Wdms Mitigation only Fix from $2,3002024-02-23 MEDIUM 5.5 CVE-2023-4587 An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered… Zem800 Firmware Mitigation only Fix from $1,6002023-09-04 CRITICAL 9.8 CVE-2023-38951 ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server vi… Biotime Mitigation only Fix from $2,3002023-08-03 HIGH 7.5 CVE-2023-38952 Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids … Biotime No fix yet Fix from $1,9502023-08-03 HIGH 7.5 CVE-2023-38949 An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web … Biotime Mitigation only Fix from $1,9502023-08-03 CRITICAL 9.8 CVE-2023-38954 ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability. Bioaccess Ivs Mitigation only Fix from $2,3002023-08-03 HIGH 7.5 CVE-2023-38955 ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses … Bioaccess Ivs Mitigation only Fix from $1,9502023-08-03 HIGH 7.5 CVE-2023-38956 A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payloa… Bioaccess Ivs Mitigation only Fix from $1,9502023-08-03 MEDIUM 5.3 CVE-2023-38958 An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platfo… Bioaccess Ivs Mitigation only Fix from $1,6002023-08-03 MEDIUM 5.3 CVE-2022-30515 ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration. Biotime No fix yet Fix from $1,6002022-11-08 HIGH 8.8 CVE-2022-36635EPSS 17% ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do. Zkbiosecurity V5000 Mitigation only Fix from $1,9502022-10-07 HIGH 8.8 CVE-2022-36634 An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request. Zkbiosecurity V5000 Mitigation only Fix from $1,9502022-10-07 CRITICAL 9.8 CVE-2020-17474 A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, … Zkbiosecurity Server No fix yet Fix from $2,3002020-08-14 MEDIUM 5.9 CVE-2020-17473 Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting toke… Zkbiosecurity Server Mitigation only Fix from $1,6002020-08-14 HIGH 8.8 CVE-2017-17056 The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function o… Zktime Web No fix yet Fix from $1,9502017-12-04 MEDIUM 6.1 CVE-2017-17057 There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in th… Zktime Web No fix yet Fix from $1,6002017-12-04 HIGH 8.0 CVE-2017-13129 Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of ad… Zktime Web Mitigation only Fix from $1,9502017-09-26 HIGH 7.5 CVE-2017-14680 ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document. Zktime Web No fix yet Fix from $1,9502017-09-21