Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Zkbio Cvsecurity CRITICAL 9.8
CVE-2025-45746

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NO…

No fix yet
Fix from $2,300 2025-05-13
Wdms MEDIUM 5.4
CVE-2023-51157

Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via…

No fix yet
Fix from $1,600 2024-09-25
Zkbio Cvsecurity CRITICAL 9.8
CVE-2024-36526

ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.

No fix yet
Fix from $2,300 2024-07-09
Zkbio Cvsecurity HIGH 8.1
CVE-2024-35433

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create…

No fix yet
Fix from $1,950 2024-05-30
Zkbio Cvsecurity HIGH 7.5
CVE-2024-35431

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server.…

No fix yet
Fix from $1,950 2024-05-30
Zkbio Cvsecurity HIGH 7.1
CVE-2024-35428

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server wh…

No fix yet
Fix from $1,950 2024-05-30
Zkbio Cvsecurity MEDIUM 6.5
CVE-2024-35429

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.

No fix yet
Fix from $1,600 2024-05-30
Zkbio Cvsecurity HIGH 8.1
CVE-2024-35430

In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the app…

No fix yet
Fix from $1,950 2024-05-30
Zkbio Cvsecurity MEDIUM 6.1
CVE-2024-35432

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Cross Site Scripting (XSS) via an Audio File. An authenticated user can injection malicious JavaScript…

No fix yet
Fix from $1,600 2024-05-30
Biotime HIGH 7.5
CVE-2023-51142

An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.

No fix yet
Fix from $1,950 2024-04-11
Biotime MEDIUM 6.5
CVE-2023-51141

An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization compone…

No fix yet
Fix from $1,600 2024-04-11
Zkbio Media HIGH 7.5
CVE-2024-2318

A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of …

Mitigation only
Fix from $1,950 2024-03-08
Zkbio Wdms CRITICAL 9.8
CVE-2024-22988

ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename …

Mitigation only
Fix from $2,300 2024-02-23
Zem800 Firmware MEDIUM 5.5
CVE-2023-4587

An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered…

Mitigation only
Fix from $1,600 2023-09-04
Biotime CRITICAL 9.8
CVE-2023-38951

ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server vi…

Mitigation only
Fix from $2,300 2023-08-03
Biotime HIGH 7.5
CVE-2023-38952

Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids …

No fix yet
Fix from $1,950 2023-08-03
Biotime HIGH 7.5
CVE-2023-38949

An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web …

Mitigation only
Fix from $1,950 2023-08-03
Bioaccess Ivs CRITICAL 9.8
CVE-2023-38954

ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.

Mitigation only
Fix from $2,300 2023-08-03
Bioaccess Ivs HIGH 7.5
CVE-2023-38955

ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses …

Mitigation only
Fix from $1,950 2023-08-03
Bioaccess Ivs HIGH 7.5
CVE-2023-38956

A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payloa…

Mitigation only
Fix from $1,950 2023-08-03
Bioaccess Ivs MEDIUM 5.3
CVE-2023-38958

An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platfo…

Mitigation only
Fix from $1,600 2023-08-03
Biotime MEDIUM 5.3
CVE-2022-30515

ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.

No fix yet
Fix from $1,600 2022-11-08
Zkbiosecurity V5000 HIGH 8.8
CVE-2022-36635EPSS 17%

ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.

Mitigation only
Fix from $1,950 2022-10-07
Zkbiosecurity V5000 HIGH 8.8
CVE-2022-36634

An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.

Mitigation only
Fix from $1,950 2022-10-07
Zkbiosecurity Server CRITICAL 9.8
CVE-2020-17474

A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, …

No fix yet
Fix from $2,300 2020-08-14
Zkbiosecurity Server MEDIUM 5.9
CVE-2020-17473

Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting toke…

Mitigation only
Fix from $1,600 2020-08-14
Zktime Web HIGH 8.8
CVE-2017-17056

The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function o…

No fix yet
Fix from $1,950 2017-12-04
Zktime Web MEDIUM 6.1
CVE-2017-17057

There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in th…

No fix yet
Fix from $1,600 2017-12-04
Zktime Web HIGH 8.0
CVE-2017-13129

Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of ad…

Mitigation only
Fix from $1,950 2017-09-26
Zktime Web HIGH 7.5
CVE-2017-14680

ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.

No fix yet
Fix from $1,950 2017-09-21