Show filters
35 Total Results
Displaying 1-10 of 35
Sort by:
Attacker Value
Very High

CVE-2017-7921

Disclosure Date: May 06, 2017 (last updated November 26, 2024)
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.
5
Attacker Value
Unknown

CVE-2021-36260

Disclosure Date: September 22, 2021 (last updated February 23, 2025)
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
Attacker Value
Unknown

CVE-2024-47487

Disclosure Date: October 18, 2024 (last updated October 23, 2024)
There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries.
Attacker Value
Unknown

CVE-2024-47486

Disclosure Date: October 18, 2024 (last updated October 23, 2024)
There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.
Attacker Value
Unknown

CVE-2024-47485

Disclosure Date: October 18, 2024 (last updated October 23, 2024)
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.
Attacker Value
Unknown

CVE-2024-29949

Disclosure Date: April 02, 2024 (last updated April 03, 2024)
There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.
0
Attacker Value
Unknown

CVE-2024-29948

Disclosure Date: April 02, 2024 (last updated April 03, 2024)
There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable device, causing a service abnormality.
0
Attacker Value
Unknown

CVE-2024-29947

Disclosure Date: April 02, 2024 (last updated April 03, 2024)
There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an attacker may send specially crafted messages to an affected product, causing a process abnormality.
0
Attacker Value
Unknown

CVE-2024-25064

Disclosure Date: March 02, 2024 (last updated March 05, 2024)
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
Attacker Value
Unknown

CVE-2024-25063

Disclosure Date: March 02, 2024 (last updated March 05, 2024)
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.