Camera
20 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Camera, a product in the mobile apps space. Use it to gauge the current risk picture and drill into individual advisories.
Camera CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 2 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 20 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High7
- Medium8
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Camera.
- CVE-2026-21014Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability.2.8
- CVE-2023-21482Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to install package through G...6.1
- CVE-2025-8613Vacron Camera ping Command Injection Remote Code Execution Vulnerability7.2
- CVE-2025-1338NUUO Camera handle_config.php print_file command injection7.3
- CVE-2024-11136Arbitrary file removal via path traversal in TCL Camera—
- CVE-2024-20854Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers...5.9
- CVE-2024-2995NUUO Camera deletefile.php denial of service5.4
- CVE-2023-30730Implicit intent hijacking vulnerability in Camera prior to versions 11.0.16.43 in Android 11, 12.1.00.30, 12.0.07.53, 12.1.03.10 in Android 12, and 13.0.01.43, 13.1.00.83 in Android 13 allows local...3.3
- CVE-2022-33712Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.5.3
- CVE-2022-23998Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a pictu...6.2
- CVE-2019-14458VIVOTEK IP Camera devices with firmware before 0x20x allow a denial of service via a crafted HTTP header.7.5
- CVE-2019-10256An authentication bypass vulnerability in VIVOTEK IPCam versions prior to 0x13a was found.9.8
- CVE-2019-14457VIVOTEK IP Camera devices with firmware before 0x20x have a stack-based buffer overflow via a crafted HTTP header.9.8
- CVE-2018-18005Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript via a URL query string parameter.6.1
- CVE-2018-18244Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header.6.1
Product grouping is registry-driven, with AI assist and human review. How it works