Export limit exceeded: 394856 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (6 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-68953 | 1 Digital Watchdog | 5 Va1g4 Recorder, Vg4 Recorder, Vmax A1 G4 Dvr and 2 more | 2026-09-17 | 6.5 Medium |
| The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests. | ||||
| CVE-2026-66890 | 1 Digital Watchdog | 5 Va1g4 Recorder, Vg4 Recorder, Vmax A1 G4 Dvr and 2 more | 2026-09-17 | 9.6 Critical |
| The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable. | ||||
| CVE-2026-68070 | 1 Digital Watchdog | 5 Va1g4 Recorder, Vg4 Recorder, Vmax A1 G4 Dvr and 2 more | 2026-09-17 | 8.8 High |
| The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command. | ||||
| CVE-2026-68950 | 1 Digital Watchdog | 5 Va1g4 Recorder, Vg4 Recorder, Vmax A1 G4 Dvr and 2 more | 2026-09-17 | 8.8 High |
| The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable. | ||||
| CVE-2026-66887 | 1 Digital Watchdog | 5 Va1g4 Recorder, Vg4 Recorder, Vmax A1 G4 Dvr and 2 more | 2026-09-17 | 9.6 Critical |
| The affected products are missing authorization on state-changing CGIs and session checks are not performed. | ||||
| CVE-2026-66372 | 1 Digital Watchdog | 5 Va1g4 Recorder, Vg4 Recorder, Vmax A1 G4 Dvr and 2 more | 2026-09-17 | 6.8 Medium |
| The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space. | ||||
Page 1 of 1.