Dvr
15 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Dvr, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
Dvr CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 4 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 15 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High6
- Medium5
Latest CVEs
The 15 most recently published vulnerabilities affecting Dvr.
- CVE-2019-25240Rifatron 5brid DVR 5brid DVR (HD6-532/516, DX6-516/508/504, MX6-516/508/504, EH6-504) Unauthenticated Live Stream Disclosure via animate.cgi9.8
- CVE-2016-15047AVTECH CloudSetup.cgi Authenticated Command Injection8.8
- CVE-2025-34056AVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution9.9
- CVE-2025-34055AVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution9.9
- CVE-2025-34054AVTECH IP camera, DVR, and NVR Devices Unauthenticated Command Injection10.0
- CVE-2025-34050AVTECH IP Camera, DVR, and NVR Devices Cross-Site Request Forgery4.3
- CVE-2023-45801Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0. 7.5
- CVE-2023-23458Sunell DVR – Exposure of Sensitive Information6.5
- CVE-2023-23463 Sunell DVR – Insufficiently Protected Credentials5.3
- CVE-2022-25012Argus Surveillance DVR v4.0 employs weak password encryption.5.5
- CVE-2020-3924TONNET DVR – Firmware Injection6.4
- CVE-2020-3923TONNET DVR – Broken Access Control8.1
- CVE-2018-15745Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.7.5
- CVE-2013-6023Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI.7.8
- CVE-2013-3586Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.7.6
Product grouping is registry-driven, with AI assist and human review. How it works