← Back

Hikcentral Professional

hikcentral_professional

Vendor: Hikvision • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hikvision
1Hikcentral Professional
Jun 17, 2026
Oct 18, 2024
7.2 HIGH· v4
8.8 HIGH· v3
N/A· v2
There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries.
1Hikvision
1Hikcentral Professional
Jun 17, 2026
Mar 2, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
1Hikvision
1Hikcentral Professional
Jun 17, 2026
Mar 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.