Vendor
ISpyConnect
Products
2
CVEs
6
Across products
6
Status
Private
Products
2- 4 CVEs
- 2 CVEs
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29775 | Cri | 0.68 | 9.8 | 0.61 | Jun 21, 2022 | iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL. | ||
| CVE-2022-29774 | Cri | 0.64 | 9.8 | 0.06 | Jun 21, 2022 | iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal. | ||
| CVE-2024-22515 | Hig | 0.57 | 8.8 | 0.01 | Feb 6, 2024 | Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component. | ||
| CVE-2024-22514 | Hig | 0.57 | 8.8 | 0.01 | Feb 6, 2024 | An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file. | ||
| CVE-2025-63408 | Hig | 0.51 | 7.8 | 0.00 | Nov 18, 2025 | Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive information, cause a server-side forgery request (SSRF), or execute OS commands. | ||
| CVE-2020-13093 | Med | 0.35 | 5.3 | 0.01 | May 15, 2020 | iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal. |
- risk 0.68cvss 9.8epss 0.61
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
- risk 0.64cvss 9.8epss 0.06
iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.
- risk 0.57cvss 8.8epss 0.01
Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component.
- risk 0.57cvss 8.8epss 0.01
An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.
- risk 0.51cvss 7.8epss 0.00
Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive information, cause a server-side forgery request (SSRF), or execute OS commands.
- risk 0.35cvss 5.3epss 0.01
iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.