Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2024-13966 ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '12345… Biotime 9.0.4+ Fix from $1,9502025-05-27 CRITICAL 9.8 CVE-2025-45746 In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NO… Zkbio Cvsecurity No fix yet Fix from $2,3002025-05-13 MEDIUM 5.4 CVE-2023-51157 Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via… Wdms No fix yet Fix from $1,6002024-09-25 CRITICAL 9.8 CVE-2024-36526 ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key. Zkbio Cvsecurity No fix yet Fix from $2,3002024-07-09 MEDIUM 5.4 CVE-2024-6523 A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown function of the component syst… Biotime after 9.5.2 Fix from $1,6002024-07-05 HIGH 8.1 CVE-2024-35433 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create… Zkbio Cvsecurity No fix yet Fix from $1,9502024-05-30 HIGH 7.5 CVE-2024-35431 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server.… Zkbio Cvsecurity No fix yet Fix from $1,9502024-05-30 HIGH 7.1 CVE-2024-35428 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server wh… Zkbio Cvsecurity No fix yet Fix from $1,9502024-05-30 MEDIUM 6.5 CVE-2024-35429 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord. Zkbio Cvsecurity No fix yet Fix from $1,6002024-05-30 HIGH 8.1 CVE-2024-35430 In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the app… Zkbio Cvsecurity No fix yet Fix from $1,9502024-05-30 MEDIUM 6.1 CVE-2024-35432 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Cross Site Scripting (XSS) via an Audio File. An authenticated user can injection malicious JavaScript… Zkbio Cvsecurity No fix yet Fix from $1,6002024-05-30 HIGH 7.5 CVE-2023-51142 An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information. Biotime No fix yet Fix from $1,9502024-04-11 MEDIUM 6.5 CVE-2023-51141 An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization compone… Biotime No fix yet Fix from $1,6002024-04-11 HIGH 7.5 CVE-2024-2318 A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of … Zkbio Media Mitigation only Fix from $1,9502024-03-08 CRITICAL 9.8 CVE-2024-22988 ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename … Zkbio Wdms Mitigation only Fix from $2,3002024-02-23 MEDIUM 5.4 CVE-2024-1706 A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. … Zkbio Access Ivs after 3.3.2 Fix from $1,6002024-02-21 MEDIUM 5.5 CVE-2023-4587 An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered… Zem800 Firmware Mitigation only Fix from $1,6002023-09-04 CRITICAL 9.8 CVE-2023-38951 ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server vi… Biotime Mitigation only Fix from $2,3002023-08-03 HIGH 7.5 CVE-2023-38950 KEVEPSS 85% A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a cr… Biotime 9.0.1+ Fix from $1,9502023-08-03 HIGH 7.5 CVE-2023-38952 Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids … Biotime No fix yet Fix from $1,9502023-08-03 HIGH 7.5 CVE-2023-38949 An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web … Biotime Mitigation only Fix from $1,9502023-08-03 CRITICAL 9.8 CVE-2023-38954 ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability. Bioaccess Ivs Mitigation only Fix from $2,3002023-08-03 HIGH 7.5 CVE-2023-38955 ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses … Bioaccess Ivs Mitigation only Fix from $1,9502023-08-03 HIGH 7.5 CVE-2023-38956 A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payloa… Bioaccess Ivs Mitigation only Fix from $1,9502023-08-03 MEDIUM 5.3 CVE-2023-38958 An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platfo… Bioaccess Ivs Mitigation only Fix from $1,6002023-08-03 HIGH 7.5 CVE-2022-42953 Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?… Zmm200 Firmware 8.88 / 15.00+ Fix from $1,9502022-12-25 HIGH 7.5 CVE-2021-39434 A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 202003… Zktime after 11.1.0 Fix from $1,9502022-12-06 MEDIUM 6.8 CVE-2022-38803 Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can re… Biotime 8.5.4+ Fix from $1,6002022-11-30 MEDIUM 6.2 CVE-2022-38802 Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, time interval, attshift,… Biotime 8.5.4+ Fix from $1,6002022-11-30 MEDIUM 5.4 CVE-2022-38801 In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-site scripting. Biotime 8.5.4+ Fix from $1,6002022-11-30