| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-6006 | ZKTeco ZKBio CVSecurity V5000 Summer Schedule cross site scripting | ZKTeco | ZKBio CVSecurity V5000 | Low | 3.5 | 2024-06-15 11:31:03 | Deep Dive |
| CVE-2024-6005 | ZKTeco ZKBio CVSecurity V5000 Department Section cross site scripting | ZKTeco | ZKBio CVSecurity V5000 | Low | 3.5 | 2024-06-15 09:31:03 | Deep Dive |
| CVE-2023-3943 | Multiple buffer overflow in ZkTeco-based OEM devices | ZkTeco | ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 | Critical | 10.0 | 2024-05-21 13:32:48 | Deep Dive |
| CVE-2023-3942 | Multiple SQLi in ZkTeco-based OEM devices | ZkTeco | ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0, Standalone service v. 2.1.6-20200907 | High | 7.5 | 2024-05-21 12:23:50 | Deep Dive |
| CVE-2023-3941 | Multiple arbitrary file writes in ZkTeco-based OEM devices | ZkTeco | ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 | Critical | 10.0 | 2024-05-21 10:20:40 | Deep Dive |
| CVE-2023-3940 | Multiple arbitrary file reads in ZkTeco-based OEM devices | ZkTeco | ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 | High | 7.5 | 2024-05-21 10:15:53 | Deep Dive |
| CVE-2023-3939 | Multiple command injection in ZkTeco-based OEM devices | ZkTeco | ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 | Critical | 10.0 | 2024-05-21 09:45:01 | Deep Dive |
| CVE-2023-3938 | Bypassing ZkTeco-based OEM devices/ZKTeco biometric authentication system via SQLi in QR code | ZkTeco | ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 | Medium | 4.6 | 2024-05-21 09:32:15 | Deep Dive |
| CVE-2024-2318 | ZKTeco ZKBio Media Service Port 9999 download path traversal | ZKTeco | ZKBio Media | Medium | 4.3 | 2024-03-08 13:00:08 | Deep Dive |
| CVE-2024-1706 | ZKTeco ZKBio Access IVS Department Name Search Bar cross site scripting | ZKTeco | ZKBio Access IVS | Low | 3.5 | 2024-02-21 18:00:08 | Deep Dive |
| CVE-2023-4587 | Insecure direct object reference in ZKTeco ZEM800 | ZKTeco | ZEM800 | High | 8.3 | 2023-09-04 11:23:07 | Deep Dive |