Vendor CVEs
Hikvision
All CVEs
62 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-25064 | Med | 0.28 | 4.3 | 0.00 | Mar 2, 2024 | Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values. | ||
| CVE-2023-6894 | Med | 0.28 | 4.3 | 0.01 | Dec 17, 2023 | A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been classified as problematic. This affects an unknown part of the file access/html/system.html of the component Log File Handler. The manipulation leads to information… | ||
| CVE-2024-29948 | Low | 0.25 | 3.8 | 0.00 | Apr 2, 2024 | There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable device, causing a service abnormality. | ||
| CVE-2026-32684 | Low | 0.19 | 2.9 | 0.00 | May 12, 2026 | The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information. | ||
| CVE-2024-29947 | Low | 0.18 | 2.7 | 0.00 | Apr 2, 2024 | There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an attacker may send specially crafted messages to an affected product, causing a process abnormality. | ||
| CVE-2014-4880 | 0.09 | — | 0.71 | Dec 8, 2014 | Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote attackers to execute arbitrary code via an RTSP PLAY request with a long Authorization header. | |||
| CVE-2013-4977 | 0.04 | — | 0.17 | Mar 3, 2014 | Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause a denial of service (device crash and reboot) and possibly execute arbitrary code via a long string… | |||
| CVE-2026-61392 | Med | 0.00 | 5.3 | 0.00 | Jul 22, 2026 | There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory. | ||
| CVE-2026-61391 | Hig | 0.00 | 7.2 | 0.01 | Jul 22, 2026 | There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets. | ||
| CVE-2026-61390 | Hig | 0.00 | 7.7 | 0.00 | Jul 22, 2026 | There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets. | ||
| CVE-2026-57600 | Hig | 0.00 | 7.5 | 0.00 | Jul 22, 2026 | Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data. | ||
| CVE-2026-57599 | Med | 0.00 | 6.6 | 0.00 | Jul 22, 2026 | There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH. |
- risk 0.28cvss 4.3epss 0.00
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
- risk 0.28cvss 4.3epss 0.01
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been classified as problematic. This affects an unknown part of the file access/html/system.html of the component Log File Handler. The manipulation leads to information…
- risk 0.25cvss 3.8epss 0.00
There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable device, causing a service abnormality.
- risk 0.19cvss 2.9epss 0.00
The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information.
- risk 0.18cvss 2.7epss 0.00
There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an attacker may send specially crafted messages to an affected product, causing a process abnormality.
- CVE-2014-4880Dec 8, 2014risk 0.09cvss —epss 0.71
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote attackers to execute arbitrary code via an RTSP PLAY request with a long Authorization header.
- CVE-2013-4977Mar 3, 2014risk 0.04cvss —epss 0.17
Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause a denial of service (device crash and reboot) and possibly execute arbitrary code via a long string…
- risk 0.00cvss 5.3epss 0.00
There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.
- risk 0.00cvss 7.2epss 0.01
There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.
- risk 0.00cvss 7.7epss 0.00
There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.
- risk 0.00cvss 7.5epss 0.00
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.
- risk 0.00cvss 6.6epss 0.00
There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.
Page 2 of 2