CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “vt”

142 vulnerabilities found for “vt”

Page 1 of 8

CVE-2025-58777
HIGH7.8

VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

keyence / vt_studio
Local
Published Oct 2, 2025
Page 1 of 8
CVE-2025-61691
HIGH7.8

VT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

keyence / vt_studio
Local
Published Oct 2, 2025
CVE-2025-61692
HIGH7.8

VT STUDIO versions 8.53 and prior contain a use after free vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

keyence / vt_studio
Local
Published Oct 2, 2025
CVE-2025-34034
HIGH8.8

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain administrative access to the device’s web interface. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-26 UTC.

5vtechnologies / blue_angel_software_suite
Network
Published Jun 24, 2025
CVE-2025-34033
HIGH8.8

An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi script. The application fails to properly sanitize input before passing it to the system-level ping command. An authenticated attacker can inject arbitrary commands by appending shell metacharacters to the ping_addr parameter in a crafted GET request to /cgi-bin/webctrl.cgi?action=pingtest_update. The command's output is reflected in the application's web interface, enabling attackers to view results directly. Default and backdoor credentials can be used to access the interface and exploit the issue. Successful exploitation results in arbitrary command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-26 UTC.

5vtechnologies / blue_angel_software_suite
Network
Published Jun 24, 2025
CVE-2025-34036
CRITICAL9.8

An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 82. The web interface fails to sanitize input in the URI path passed to the language extraction functionality. When the server processes a request to /language/[lang]/index.html, it uses the [lang] input unsafely in a tar extraction command without proper escaping. This allows an unauthenticated remote attacker to inject shell commands and achieve arbitrary command execution as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

tvt / td-2108ts-cl_firmware+29
Network
Published Jun 24, 2025
CVE-2024-29219
HIGH7.8

Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file.

keyence / kv_replay_viewer+3
Local
Published Apr 15, 2024
CVE-2024-28099
HIGH7.8

VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.

keyence / vt_studio
Local
Published Apr 15, 2024
CVE-2024-29218
HIGH8.8

Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier, KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file.

keyence / kv_replay_viewer+3
Network
Published Apr 15, 2024
CVE-2023-29861
CRITICAL9.8

An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.

flir / dvtel_camera_firmware
Network
Published May 15, 2023
CVE-2021-33046
CRITICAL9.8

Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.

dahuasecurity / ipc-hx1xxx_firmware+27
Network
Published Jan 13, 2022
CVE-2021-20601
HIGH7.5

Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all versions, GOT2000 series GT23 model all versions, GOT2000 series GT21 model all versions, GOT SIMPLE series GS21 model all versions, and GT SoftGOT2000 all versions allows an remote unauthenticated attacker to write a value that exceeds the configured input range limit by sending a malicious packet to rewrite the device value. As a result, the system operation may be affected, such as malfunction.

mitsubishielectric / gt_softgot2000+49
Network
Published Nov 23, 2021
CVE-2021-33044
CRITICAL9.8

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

dahuasecurity / ipc-hum7xxx_firmware+18
Network
Published Sep 15, 2021
CVE-2021-33045
CRITICAL9.8

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

dahuasecurity / ipc-hum7xxx_firmware+18
Network
Published Sep 15, 2021
CVE-2020-10227
MEDIUM6.1

A cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arbitrary JavaScript code via the From field of an email.

vtenext / vtenext
Network
Published Sep 14, 2020
CVE-2020-10228
HIGH8.8

A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution.

vtenext / vtenext
Network
Published Sep 14, 2020
CVE-2019-13379
HIGH8.8

On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.

avtech / room_alert_3e_firmware
Network
Published Jul 7, 2019
CVE-2018-4022
HIGH7.8

A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A specially crafted MKV file can cause arbitrary code execution in the context of the current user.

mkvtoolnix / mkvinfo
Local
Published Oct 26, 2018
CVE-2018-13589
HIGH7.5

The mintToken function of a smart contract implementation for MooAdvToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

mooadvtoken_project / mooadvtoken
Network
Published Jul 9, 2018
CVE-2018-8754
MEDIUM5.5

The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values of user SID data size, strings size, or data size. NOTE: the vendor has disputed this as described in libyal/libevt issue 5 on GitHub

libevt_project / libevt+1
Local
Published Mar 18, 2018