Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nvrsolo Firmware MEDIUM 6.1
CVE-2022-33119

NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.

No fix yet
Fix from $1,600 2022-06-21
Network Video Recorder Firmware CRITICAL 9.8
CVE-2022-25521

NUUO v03.11.00 was discovered to contain access control issue.

Fix: after 1.0
Fix from $2,300 2022-03-29
Nvrmini2 Firmware CRITICAL 9.8
CVE-2022-23227 KEVEPSS 49%

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because …

Fix: after 3.11.0
Fix from $2,300 2022-01-14
Nvrsolo Firmware MEDIUM 6.1
CVE-2021-45812

NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by inje…

No fix yet
Fix from $1,600 2021-12-28
Network Video Recorder Firmware CRITICAL 9.8
CVE-2019-9653EPSS 11%

NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to h…

Fix: after 3.3.0
Fix from $2,300 2019-05-31
Nvrmini2 Firmware CRITICAL 9.8
CVE-2018-19864EPSS 25%

NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer ov…

Fix: after 3.9.1
Fix from $2,300 2018-12-05
Nvrmini2 Firmware HIGH 8.8
CVE-2018-15716EPSS 18%

NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to e…

No fix yet
Fix from $1,950 2018-11-30
Nuuo Cms CRITICAL 9.8
CVE-2018-17934EPSS 20%

NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended di…

Fix: after 3.3
Fix from $2,300 2018-11-27
Nuuo Cms CRITICAL 9.8
CVE-2018-17936EPSS 15%

NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the serv…

Fix: after 3.3
Fix from $2,300 2018-11-27
Nuuo Cms HIGH 8.8
CVE-2018-18982EPSS 61%

NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an …

Fix: after 3.3
Fix from $1,950 2018-11-27
Nuuo Cms CRITICAL 9.8
CVE-2018-17888EPSS 30%

NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session …

Fix: after 3.1
Fix from $2,300 2018-10-12
Nuuo Cms CRITICAL 9.8
CVE-2018-17890

NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, which could allow arbitrary co…

Fix: after 3.1
Fix from $2,300 2018-10-12
Nuuo Cms CRITICAL 9.8
CVE-2018-17894

NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which could allow an attacker to gain p…

Fix: after 3.1
Fix from $2,300 2018-10-12
Nuuo Cms HIGH 8.8
CVE-2018-17892

NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard account security features to no…

Fix: after 3.1
Fix from $1,950 2018-10-12
Nvrmini2 Firmware CRITICAL 9.8
CVE-2018-1149EPSS 15%

cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests.

Fix: after 3.8.0
Fix from $2,300 2018-09-19
Nvrmini2 Firmware HIGH 7.3
CVE-2018-1150

NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over user accounts if the file /tmp/m…

Fix: after 3.8.0
Fix from $1,950 2018-09-19
Nvrmini Firmware CRITICAL 9.8
CVE-2018-14933 KEVEPSS 95%

upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir c…

Mitigation only
Fix from $2,300 2018-08-04
Nt 4040 Titan Firmware CRITICAL 9.8
CVE-2016-6553

Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and localdisplay:111111. A remote netw…

Mitigation only
Fix from $2,300 2018-07-13
Nvrmini 2 Firmware CRITICAL 9.8
CVE-2018-11523EPSS 10%

upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.

Fix: after 3.6.5
Fix from $2,300 2018-05-29
Nvrmini 2 HIGH 8.8
CVE-2016-5680EPSS 17%

Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authentic…

No fix yet
Fix from $1,950 2016-08-31
Nvrmini 2 HIGH 8.8
CVE-2016-5679EPSS 14%

cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary…

No fix yet
Fix from $1,950 2016-08-31
Nvrmini 2 CRITICAL 9.8
CVE-2016-5678EPSS 9%

NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain admi…

No fix yet
Fix from $2,300 2016-08-31