← Back

Hikcentral Professional

hikcentral_professional

Vendor: Hikvision • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hikvision
1Hikcentral Professional
Mar 19, 2025
Oct 18, 2024
7.2 HIGH· v4
8.8 HIGH· v3
N/A· v2
There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries.
1Hikvision
1Hikcentral Professional
Nov 21, 2024
Mar 2, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
1Hikvision
1Hikcentral Professional
Mar 27, 2025
Mar 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.