vciy

CVEs we hold for Zkteco

Records whose assigning authority named Zkteco as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8598Unauthenticated Export Service in ZKTeco CCTV CamerasZKTeco SSC335-GC2063-Face-0b77 Solution Camera
CVE-2025-55280Information Disclosure Vulnerability in ZKTeco WL20ZKTeco Co WL20 Biometric Attendance System
CVE-2025-55279Hard-coded Private Key Vulnerability in ZKTeco WL20ZKTeco Co WL20 Biometric Attendance System
CVE-2025-54465Hard-coded Credentials Vulnerability in ZKTeco WL20ZKTeco Co WL20 Biometric Attendance System
CVE-2025-54464Cleartext Storage Vulnerability in ZKTeco WL20ZKTeco Co WL20 Biometric Attendance System
CVE-2025-45746no title heldZKTeco ZKBio CVSecurity
CVE-2025-15128ZKTeco BioTime Endpoint safe_setting credentials storageZKTeco BioTime
CVE-2024-6523ZKTeco BioTime system-group-add cross site scriptingZKTeco BioTime
CVE-2024-6344ZKTeco ZKBio CVSecurity V5000 Push Configuration Section cross site scriptingZKTeco ZKBio CVSecurity V5000
CVE-2024-6006ZKTeco ZKBio CVSecurity V5000 Summer Schedule cross site scriptingZKTeco ZKBio CVSecurity V5000
CVE-2024-6005ZKTeco ZKBio CVSecurity V5000 Department Section cross site scriptingZKTeco ZKBio CVSecurity V5000
CVE-2024-45250ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized ActorZKteco iClock v3.1-168
CVE-2024-2318ZKTeco ZKBio Media Service Port 9999 download path traversalZKTeco ZKBio Media
CVE-2024-1706ZKTeco ZKBio Access IVS Department Name Search Bar cross site scriptingZKTeco ZKBio Access IVS
CVE-2024-13966ZKTeco BioTime default passwordZKTeco BioTime
CVE-2024-11049ZKTeco ZKBio Time Image File photo direct requestZKTeco ZKBio Time
CVE-2023-4587Insecure direct object reference in ZKTeco ZEM800ZKTeco ZEM800
CVE-2023-3943Multiple buffer overflow in ZkTeco-based OEM devicesZkTeco-based OEM devices with firmware…
CVE-2023-3942Multiple SQLi in ZkTeco-based OEM devicesZkTeco-based OEM devices with firmware…
CVE-2023-3941Multiple arbitrary file writes in ZkTeco-based OEM devicesZkTeco-based OEM devices with firmware…
CVE-2023-3940Multiple arbitrary file reads in ZkTeco-based OEM devicesZkTeco-based OEM devices with firmware…
CVE-2023-3939Multiple command injection in ZkTeco-based OEM devicesZkTeco-based OEM devices with firmware…
CVE-2023-3938Bypassing ZkTeco-based OEM devices/ZKTeco biometric authentication system via SQLi in QR codeZkTeco-based OEM devices with firmware…
CVE-2016-20032ZKTeco ZKAccess Security System 5.3.1 Stored XSSZKTeco ZKAccess Security System
CVE-2016-20031ZKTeco ZKBioSecurity 3.0 Local Authorization Bypass via visLogin.jspZKTeco ZKBioSecurity
CVE-2016-20030ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginActionZKTeco ZKBioSecurity
CVE-2016-20029ZKTeco ZKBioSecurity 3.0 File Path Manipulation VulnerabilityZKTeco ZKBioSecurity
CVE-2016-20028ZKTeco ZKBioSecurity 3.0 Cross-Site Request Forgery SuperadminZKTeco ZKBioSecurity
CVE-2016-20027ZKTeco ZKBioSecurity 3.0 Multiple Reflected XSS VulnerabilitiesZKTeco ZKBioSecurity
CVE-2016-20026ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code ExecutionZKTeco ZKBioSecurity
CVE-2016-20025ZKTeco ZKAccess Professional 3.5.3 Privilege Escalation via Insecure PermissionsZKTeco ZKAccess Professional
CVE-2016-20024ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege EscalationZKTeco ZKTime.Net

32 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.