Vendor CVEs
Hikvision
All CVEs
60 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32684 | Low | 0.19 | 2.9 | 0.00 | May 12, 2026 | The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information. | ||
| CVE-2024-29947 | Low | 0.18 | 2.7 | 0.00 | Apr 2, 2024 | There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an attacker may send specially crafted messages to an affected product, causing a process abnormality. | ||
| CVE-2014-4880 | 0.09 | — | 0.70 | Dec 8, 2014 | Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote attackers to execute arbitrary code via an RTSP PLAY request with a long Authorization header. | |||
| CVE-2013-4977 | 0.04 | — | 0.17 | Mar 3, 2014 | Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause a denial of service (device crash and reboot) and possibly execute arbitrary code via a long string… | |||
| CVE-2026-16843 | Hig | 0.00 | 7.2 | 0.01 | Jul 31, 2026 | Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary… | ||
| CVE-2026-61392 | Med | 0.00 | 5.3 | 0.00 | Jul 22, 2026 | There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory. | ||
| CVE-2026-61391 | Hig | 0.00 | 7.2 | 0.00 | Jul 22, 2026 | There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets. | ||
| CVE-2026-61390 | Hig | 0.00 | 7.7 | 0.00 | Jul 22, 2026 | There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets. | ||
| CVE-2026-57600 | Hig | 0.00 | 7.5 | 0.00 | Jul 22, 2026 | Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data. | ||
| CVE-2026-57599 | Med | 0.00 | 6.6 | 0.00 | Jul 22, 2026 | There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH. |
- risk 0.19cvss 2.9epss 0.00
The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information.
- risk 0.18cvss 2.7epss 0.00
There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an attacker may send specially crafted messages to an affected product, causing a process abnormality.
- CVE-2014-4880Dec 8, 2014risk 0.09cvss —epss 0.70
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote attackers to execute arbitrary code via an RTSP PLAY request with a long Authorization header.
- CVE-2013-4977Mar 3, 2014risk 0.04cvss —epss 0.17
Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause a denial of service (device crash and reboot) and possibly execute arbitrary code via a long string…
- risk 0.00cvss 7.2epss 0.01
Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary…
- risk 0.00cvss 5.3epss 0.00
There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.
- risk 0.00cvss 7.2epss 0.00
There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.
- risk 0.00cvss 7.7epss 0.00
There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.
- risk 0.00cvss 7.5epss 0.00
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.
- risk 0.00cvss 6.6epss 0.00
There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.
Page 2 of 2