VYPR
Vendor

Hikvision

Products
450
CVEs
60
Across products
88
Status
Private

Products

450
View all 450 products →

Recent CVEs

60
View all 60 CVEs →
  • CVE-2021-36260CriKEVSep 22, 2021
    risk 0.87cvss 9.8epss 1.00

    A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

  • CVE-2017-7921CriKEVMay 6, 2017
    risk 0.87cvss 9.8epss 1.00

    An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series…

  • CVE-2013-4976CriDec 27, 2019
    risk 0.70cvss 9.8epss 0.36

    Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials

  • CVE-2025-34067CriJul 2, 2025
    risk 0.66cvss epss 0.20

    An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user…

  • CVE-2023-28815CriOct 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges and execute arbitrary commands on the system.iSecure Center is software released…

  • CVE-2023-28814CriOct 17, 2025
    risk 0.64cvss 9.8epss 0.00

    Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to be uploaded, attackers may upload malicious files to the server. iSecure Center is software released for China's domestic market…

  • CVE-2024-47485CriOct 18, 2024
    risk 0.64cvss 9.8epss 0.01

    There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.

  • CVE-2018-6414CriAug 13, 2018
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow vulnerability in the web server of some Hikvision IP Cameras allows an attacker to send a specially crafted message to affected devices. Due to the insufficient input validation, successful exploit can corrupt memory and lead to arbitrary code execution or…

  • CVE-2013-4975HigDec 27, 2019
    risk 0.61cvss 8.8epss 0.12

    Hikvision DS-2CD7153-E IP Camera has Privilege Escalation

  • CVE-2023-28812CriNov 23, 2023
    risk 0.59cvss 9.1epss 0.01

    There is a buffer overflow vulnerability in a web browser plug-in could allow an attacker to exploit the vulnerability by sending crafted messages to computers installed with this plug-in, which could lead to arbitrary code execution or cause process exception of the plug-in.

  • CVE-2023-28808CriApr 11, 2023
    risk 0.59cvss 9.1epss 0.01

    Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.

  • CVE-2022-28173CriDec 19, 2022
    risk 0.59cvss 9.1epss 0.01

    The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.

  • CVE-2025-66177HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched…

  • CVE-2025-66176HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.01

    There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched…

  • CVE-2025-34058HigJul 1, 2025
    risk 0.57cvss epss 0.01

    Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the…

  • CVE-2024-47487HigOct 18, 2024
    risk 0.57cvss 8.8epss 0.00

    There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries.

  • CVE-2017-7923HigMay 6, 2017
    risk 0.57cvss 8.8epss 0.02

    A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD…

  • CVE-2025-39247HigAug 29, 2025
    risk 0.56cvss 8.6epss 0.00

    There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.

  • CVE-2022-28171HigJun 27, 2022
    risk 0.56cvss 7.5epss 0.50

    The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the…

  • CVE-2024-58274HigOct 22, 2025
    risk 0.55cvss 8.3epss 0.18

    Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.