Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Very High
CVE-2021-33045
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
1
Attacker Value
Unknown
CVE-2023-6919
Disclosure Date: January 26, 2024 (last updated February 02, 2024)
Path Traversal: '/../filedir' vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard allows Absolute Path Traversal.This issue affects VGuard: before V500.0003.R008.4011.C0012.B351.C.
0
Attacker Value
Unknown
CVE-2023-7227
Disclosure Date: January 25, 2024 (last updated February 01, 2024)
SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.
0
Attacker Value
Unknown
CVE-2023-28811
Disclosure Date: November 23, 2023 (last updated December 09, 2023)
There is a buffer overflow in the password recovery feature of Hikvision NVR/DVR models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.
0
Attacker Value
Unknown
CVE-2021-44954
Disclosure Date: July 18, 2022 (last updated October 07, 2023)
In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a Sudo misconfiguration.
0
Attacker Value
Unknown
CVE-2021-41419
Disclosure Date: July 18, 2022 (last updated October 07, 2023)
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
0
Attacker Value
Unknown
CVE-2021-34346
Disclosure Date: September 10, 2021 (last updated February 23, 2025)
A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03 ) and later
0
Attacker Value
Unknown
CVE-2020-26097
Disclosure Date: November 18, 2020 (last updated February 22, 2025)
The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing telnet on the Internet, remote root access on the device is possible. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2015-2909
Disclosure Date: February 06, 2020 (last updated February 21, 2025)
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The user is presented with clear warnings on the GUI that they should set usernames and passwords."
0
Attacker Value
Unknown
CVE-2020-6960
Disclosure Date: January 22, 2020 (last updated February 21, 2025)
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges.
0