resources
Camera CVE tracker
This page lists published camera, NVR, and DVR CVEs and flags which ones CISA has listed as exploited in the wild. 173 rows on this build, 21 of them from the Known Exploited Vulnerabilities catalog.
Updated August 19, 2026. Sources: the CISA Known Exploited Vulnerabilities catalog, Axis security advisories, Bosch PSIRT, and Hanwha Vision S-CERT. Free to cite with a link.
173
Published camera CVEs on this page
21
Of those, listed in KEV
152
Axis, Bosch, or Hanwha published
0
Axis, Bosch, or Hanwha in KEV
A published CVE means a vulnerability was documented. A KEV Yes means CISA has evidence it has been used. Most camera CVEs never make the KEV catalog. The ones that do are the doors that already opened somewhere, which is why patch latency on those rows is a fleet problem rather than a research problem. How those doors get walked, and what closes them, is in IP camera vulnerabilities.
Axis, Bosch, and Hanwha publish camera CVEs on their own advisory pages, and those rows are in this table. CISA currently lists none of them as exploited in the wild. That is a statement about KEV, not a claim those products have no vulnerabilities.
the table
Published camera-shaped CVEs, current as of August 19, 2026.
173 rows. Matching is on CVE identifier, vendor, product, vulnerability name, and camera model. A model search shows that vendor's camera CVEs, not a per-model affected list. Default order is in-the-wild first, then date.
No match in this table. Rows are CVE-level (AXIS OS, Bosch CPP, Hanwha cameras, or a KEV product string), not a list of every model. Absence from KEV is not a clean bill of health.
| CVE | Vendor | Product | In the wild | Date | CWE |
|---|---|---|---|---|---|
| CVE-2017-7921 | Hikvision | Multiple Products | Mar 5, 2026 | CWE-287 | |
| CVE-2023-52163 | Digiever | DS-2105 Pro | Dec 22, 2025 | CWE-862 | |
| CVE-2022-40799 | D-Link | DNR-322L | Aug 5, 2025 | CWE-494 | |
| CVE-2020-25079 | D-Link | DCS-2530L and DCS-2670L Devices | Aug 5, 2025 | CWE-77 | |
| CVE-2020-25078 | D-Link | DCS-2530L and DCS-2670L Devices | Aug 5, 2025 | none | |
| CVE-2024-6047 | GeoVision | Multiple Devices | May 7, 2025 | CWE-78 | |
| CVE-2024-11120 | GeoVision | Multiple Devices | May 7, 2025 | CWE-78 | |
| CVE-2025-1316 | Edimax | IC-7100 IP Camera | Mar 19, 2025 | CWE-78 | |
| CVE-2022-23227 | NUUO | NVRmini2 Devices | Dec 18, 2024 | CWE-306 | |
| CVE-2021-40407 | Reolink | RLC-410W IP Camera | Dec 18, 2024 | CWE-78 | |
| CVE-2019-11001 | Reolink | Multiple IP Cameras | Dec 18, 2024 | CWE-78 | |
| CVE-2018-14933 | NUUO | NVRmini Devices | Dec 18, 2024 | CWE-78 | |
| CVE-2024-8957 | PTZOptics | PT30X-SDI/NDI Cameras | Nov 4, 2024 | CWE-78 | |
| CVE-2024-8956 | PTZOptics | PT30X-SDI/NDI Cameras | Nov 4, 2024 | CWE-287 | |
| CVE-2021-33045 | Dahua | IP Camera Firmware | Aug 21, 2024 | CWE-287 | |
| CVE-2021-33044 | Dahua | IP Camera Firmware | Aug 21, 2024 | CWE-287 | |
| CVE-2023-47565 | QNAP | VioStor NVR | Dec 21, 2023 | CWE-78 | |
| CVE-2016-11021 | D-Link | DCS-930L Devices | Mar 25, 2022 | CWE-78 | |
| CVE-2021-36260 | Hikvision | Security cameras web server | Jan 10, 2022 | CWE-78 | |
| CVE-2020-5735 | Amcrest | Cameras and Network Video Recorder (NVR) | Nov 3, 2021 | CWE-121 | |
| CVE-2019-20085 | TVT | NVMS-1000 | Nov 3, 2021 | CWE-22 | |
| CVE-2026-6505 | Axis | AXIS OS | none | ||
| CVE-2026-6181 | Axis | AXIS OS | none | ||
| CVE-2026-5304 | Axis | AXIS OS | none | ||
| CVE-2026-5303 | Axis | AXIS OS | none | ||
| CVE-2026-4757 | Axis | AXIS OS | none | ||
| CVE-2026-1185 | Axis | AXIS OS | none | ||
| CVE-2026-0804 | Axis | AXIS OS | none | ||
| CVE-2026-0802 | Axis | AXIS OS | none | ||
| CVE-2026-0541 | Axis | AXIS OS | none | ||
| CVE-2025-52601 | Hanwha | Cameras | none | ||
| CVE-2025-52600 | Hanwha | Cameras | none | ||
| CVE-2025-52599 | Hanwha | Cameras | none | ||
| CVE-2025-52598 | Hanwha | Cameras | none | ||
| CVE-2025-30027 | Axis | AXIS OS | none | ||
| CVE-2025-11142 | Axis | AXIS OS | none | ||
| CVE-2025-9524 | Axis | AXIS OS | none | ||
| CVE-2025-9055 | Axis | AXIS OS | none | ||
| CVE-2025-8998 | Axis | AXIS OS | none | ||
| CVE-2025-8108 | Axis | AXIS OS | none | ||
| CVE-2025-8075 | Hanwha | Cameras | none | ||
| CVE-2025-6779 | Axis | AXIS OS | none | ||
| CVE-2025-6571 | Axis | AXIS OS | none | ||
| CVE-2025-6298 | Axis | AXIS OS | none | ||
| CVE-2025-5718 | Axis | AXIS OS | none | ||
| CVE-2025-5454 | Axis | AXIS OS | none | ||
| CVE-2025-5452 | Axis | AXIS OS | none | ||
| CVE-2025-4645 | Axis | AXIS OS | none | ||
| CVE-2025-3892 | Axis | AXIS OS | none | ||
| CVE-2025-0361 | Axis | AXIS OS | none | ||
| CVE-2025-0360 | Axis | AXIS OS | none | ||
| CVE-2025-0359 | Axis | AXIS OS | none | ||
| CVE-2025-0358 | Axis | AXIS OS | none | ||
| CVE-2025-0325 | Axis | AXIS OS | none | ||
| CVE-2025-0324 | Axis | AXIS OS | none | ||
| CVE-2024-58330 | Bosch | IP cameras (CPP) | Aug 21, 2024 | none | |
| CVE-2024-54013 | Hanwha | Cameras | none | ||
| CVE-2024-54012 | Hanwha | Cameras | none | ||
| CVE-2024-54011 | Hanwha | Cameras | none | ||
| CVE-2024-47262 | Axis | AXIS OS | none | ||
| CVE-2024-47261 | Axis | AXIS OS | none | ||
| CVE-2024-47260 | Axis | AXIS OS | none | ||
| CVE-2024-47259 | Axis | AXIS OS | none | ||
| CVE-2024-47257 | Axis | AXIS OS | none | ||
| CVE-2024-41887 | Hanwha | NVR | none | ||
| CVE-2024-41886 | Hanwha | NVR | none | ||
| CVE-2024-41885 | Hanwha | NVR | none | ||
| CVE-2024-41884 | Hanwha | NVR | none | ||
| CVE-2024-41883 | Hanwha | NVR | none | ||
| CVE-2024-41882 | Hanwha | NVR | none | ||
| CVE-2024-8772 | Axis | AXIS OS | none | ||
| CVE-2024-8160 | Axis | AXIS OS | none | ||
| CVE-2024-7784 | Axis | AXIS OS | none | ||
| CVE-2024-6979 | Axis | AXIS OS | none | ||
| CVE-2024-6509 | Axis | AXIS OS | none | ||
| CVE-2024-6173 | Axis | AXIS OS | none | ||
| CVE-2024-0067 | Axis | AXIS OS | none | ||
| CVE-2024-0066 | Axis | AXIS OS | none | ||
| CVE-2024-0055 | Axis | AXIS OS | none | ||
| CVE-2024-0054 | Axis | AXIS OS | none | ||
| CVE-2023-39509 | Bosch | IP cameras (CPP) | Dec 13, 2023 | none | |
| CVE-2023-5747 | Hanwha | Cameras | Nov 13, 2023 | none | |
| CVE-2022-41677 | Bosch | IP cameras (CPP) | Jun 28, 2023 | none | |
| CVE-2023-32229 | Bosch | IP cameras (CPP) | May 31, 2023 | none | |
| CVE-2023-31996 | Hanwha | Cameras | May 15, 2023 | none | |
| CVE-2023-31995 | Hanwha | Cameras | May 15, 2023 | none | |
| CVE-2023-31994 | Hanwha | Cameras | May 15, 2023 | none | |
| CVE-2023-21418 | Axis | AXIS OS | none | ||
| CVE-2023-21417 | Axis | AXIS OS | none | ||
| CVE-2023-21416 | Axis | AXIS OS | none | ||
| CVE-2023-21415 | Axis | AXIS OS | none | ||
| CVE-2023-21414 | Axis | AXIS OS | none | ||
| CVE-2023-21413 | Axis | AXIS OS | none | ||
| CVE-2023-21412 | Axis | AXIS License Plate Verifier | none | ||
| CVE-2023-21411 | Axis | AXIS License Plate Verifier | none | ||
| CVE-2023-21410 | Axis | AXIS License Plate Verifier | none | ||
| CVE-2023-21409 | Axis | AXIS License Plate Verifier | none | ||
| CVE-2023-21408 | Axis | AXIS License Plate Verifier | none | ||
| CVE-2023-21407 | Axis | AXIS License Plate Verifier | none | ||
| CVE-2023-21406 | Axis | AXIS OS | none | ||
| CVE-2023-21405 | Axis | AXIS OS | none | ||
| CVE-2023-21404 | Axis | AXIS OS | none | ||
| CVE-2023-6116 | Hanwha | NVR and DVR | none | ||
| CVE-2023-6096 | Hanwha | NVR and DVR | none | ||
| CVE-2023-6095 | Hanwha | NVR and DVR | none | ||
| CVE-2023-5800 | Axis | AXIS OS | none | ||
| CVE-2023-5677 | Axis | AXIS OS | none | ||
| CVE-2023-5553 | Axis | AXIS OS | none | ||
| CVE-2023-5038 | Hanwha | Cameras | none | ||
| CVE-2023-5037 | Hanwha | Cameras | none | ||
| CVE-2021-23851 | Bosch | IP cameras (CPP) | Mar 30, 2022 | none | |
| CVE-2021-23850 | Bosch | IP cameras (CPP) | Mar 30, 2022 | none | |
| CVE-2021-32934 | Hanwha | NVR | Sep 9, 2021 | none | |
| CVE-2021-28372 | Hanwha | NVR | Sep 9, 2021 | none | |
| CVE-2021-23849 | Bosch | IP cameras (CPP) | Aug 4, 2021 | none | |
| CVE-2021-23854 | Bosch | IP cameras (CPP) | Jun 9, 2021 | none | |
| CVE-2021-23853 | Bosch | IP cameras (CPP) | Jun 9, 2021 | none | |
| CVE-2021-23852 | Bosch | IP cameras (CPP) | Jun 9, 2021 | none | |
| CVE-2021-23848 | Bosch | IP cameras (CPP) | Jun 9, 2021 | none | |
| CVE-2021-23847 | Bosch | IP cameras (CPP) | Jun 9, 2021 | none | |
| CVE-2021-3011 | Bosch | IP cameras and encoders (CPP) | Mar 3, 2021 | none | |
| CVE-2021-31988 | Axis | AXIS OS | none | ||
| CVE-2021-31987 | Axis | AXIS OS | none | ||
| CVE-2021-31986 | Axis | AXIS OS | none | ||
| CVE-2019-12223 | Hanwha | NVR | none | ||
| CVE-2018-19036 | Bosch | IP cameras (CPP) | Dec 12, 2018 | none | |
| CVE-2018-6303 | Hanwha | SmartCam | Mar 21, 2018 | none | |
| CVE-2018-6302 | Hanwha | SmartCam | Mar 21, 2018 | none | |
| CVE-2018-6301 | Hanwha | SmartCam | Mar 21, 2018 | none | |
| CVE-2018-6300 | Hanwha | SmartCam | Mar 21, 2018 | none | |
| CVE-2018-6299 | Hanwha | SmartCam | Mar 21, 2018 | none | |
| CVE-2018-6298 | Hanwha | SmartCam | Mar 21, 2018 | none | |
| CVE-2018-6297 | Hanwha | SmartCam | Mar 21, 2018 | none | |
| CVE-2018-6296 | Hanwha | SmartCam | Mar 21, 2018 | none | |
| CVE-2018-6295 | Hanwha | SmartCam | Mar 21, 2018 | none | |
| CVE-2018-6294 | Hanwha | SmartCam | Mar 21, 2018 | none | |
| CVE-2018-11689 | Hanwha | DVR | none | ||
| CVE-2018-10664 | Axis | AXIS OS | none | ||
| CVE-2018-10663 | Axis | AXIS OS | none | ||
| CVE-2018-10662 | Axis | AXIS OS | none | ||
| CVE-2018-10661 | Axis | AXIS OS | none | ||
| CVE-2018-10660 | Axis | AXIS OS | none | ||
| CVE-2018-10659 | Axis | AXIS OS | none | ||
| CVE-2018-10658 | Axis | AXIS OS | none | ||
| CVE-2018-9158 | Axis | AXIS OS | none | ||
| CVE-2017-20049 | Axis | AXIS OS | none | ||
| CVE-2017-15885 | Axis | AXIS OS | none | ||
| CVE-2017-12413 | Axis | AXIS OS | none | ||
| CVE-2017-7912 | Hanwha | NVR | none | ||
| CVE-2015-8258 | Axis | AXIS OS | none | ||
| CVE-2015-8257 | Axis | AXIS OS | none | ||
| CVE-2015-8256 | Axis | AXIS OS | none | ||
| CVE-2015-8255 | Axis | AXIS OS | none | ||
| CVE-2013-3543 | Axis | AXIS OS | none | ||
| CVE-2008-5260 | Axis | AXIS OS | none | ||
| CVE-2007-5214 | Axis | AXIS OS | none | ||
| CVE-2007-5213 | Axis | AXIS OS | none | ||
| CVE-2007-5212 | Axis | AXIS OS | none | ||
| CVE-2007-4930 | Axis | AXIS OS | none | ||
| CVE-2007-4929 | Axis | AXIS OS | none | ||
| CVE-2007-4928 | Axis | AXIS OS | none | ||
| CVE-2007-4927 | Axis | AXIS OS | none | ||
| CVE-2007-4926 | Axis | AXIS OS | none | ||
| CVE-2007-2239 | Axis | AXIS OS | none | ||
| CVE-2004-2427 | Axis | AXIS OS | none | ||
| CVE-2004-2426 | Axis | AXIS OS | none | ||
| CVE-2004-2425 | Axis | AXIS OS | none | ||
| CVE-2004-0789 | Axis | AXIS OS | none | ||
| CVE-2003-1386 | Axis | AXIS OS | none | ||
| CVE-2003-0240 | Axis | AXIS OS | none | ||
| CVE-2001-1543 | Axis | AXIS OS | none | ||
| CVE-2000-0191 | Axis | AXIS OS | none | ||
| CVE-2000-0144 | Axis | AXIS OS | none |
For KEV rows, Date is the day CISA added the identifier, not the day the CVE was published. CVE-2017-7921 is a 2017 Hikvision authentication bypass that landed on KEV in March 2026. Vendor rows use the advisory date when the vendor publishes one. Axis registry tables have no calendar column. Hanwha RSS stamps are the feed rebuild, not the advisory date, so those stay blank unless the PDF filename itself carries a date. Blank dates sort by CVE identifier.
Methodology
Two feeds, rebuilt on a monthly cadence, free to cite. The first is CISA's public KEV JSON, the same catalog CISA publishes for BOD 22-01: vulnerabilities with evidence of exploitation in the wild. This page keeps the camera-shaped slice of that catalog. The second is vendor PSIRT: Axis security advisories, Bosch PSIRT camera and CPP-titled advisories, and Hanwha Vision S-CERT vulnerability reports for cameras, NVRs, and DVRs. A CVE that appears in both feeds is one row, marked Yes for in the wild.
The KEV slice keeps a row when the vendor is a camera or recorder manufacturer (Hikvision, Dahua, Amcrest, Reolink, NUUO, PTZOptics, GeoVision, Digiever, TVT), or when the product field is camera-shaped for vendors that also ship other gear (Edimax IP cameras, QNAP VioStor NVR, D-Link DCS and DNR). Those names dominate the in-the-wild column because that catalog is the slice where CISA has evidence of exploitation. Hikvision and Dahua stay KEV-only here. This page does not scrape NVD for those brands. The slice also keeps intercoms, door stations, and network speakers when a feed lists them. Rows for fire alarm, access control, media servers, camera-upload features on non-camera products, UniFi, PBX, NAS, and the rest of a vendor's IT catalog are dropped. Axis Camera Station, AXIS Device Manager, Bosch Rexroth, Bosch MAP, and Hanwha VMS or statement PDFs are out of scope. Axis IDs still under embargo, listed without a published summary, are excluded until Axis publishes the advisory text.
Two caveats matter for interpretation. First, KEV is not a complete history of camera exploitation. CISA adds rows as evidence meets its bar, sometimes years after disclosure. Second, a listing is not a finding that a given fleet is vulnerable. The product string can be as broad as "Multiple Products" or "AXIS OS." A model search (M3005-V) maps the model to a vendor and shows that vendor's camera CVEs; it does not mean every listed CVE affects that camera. Confirm against inventory, firmware, and the vendor advisory linked from NVD. If a vendor scrape fails at refresh time, the last successful pull for that vendor is kept rather than emptying the table.
Journalists, researchers, and operators are welcome to cite and republish these figures with a link back to this page so readers can check the method and the current feeds. If a row looks wrong, write [email protected] with a source.
Questions about this tracker
What does this list include?
Published camera, NVR, and DVR CVEs from vendor advisories and from CISA KEV. Each row is flagged Yes or No for whether CISA has listed that identifier as exploited in the wild.
Can I search by camera model?
Yes. A model such as M3005-V maps to its vendor and shows that vendor's camera CVEs. Axis publishes against AXIS OS, Bosch against CPP platforms, so a model hit is not a finding that every listed CVE affects that camera. Confirm the advisory and the firmware actually running. Common current models also live on the camera firmware tracks reference.
Does a listing mean my cameras are vulnerable?
No. It means the vulnerability was published, and the In the wild column says whether CISA has evidence it has been used somewhere. Whether it applies depends on vendor, product, firmware, and whether the management path is reachable.
Why is the Axis, Bosch, and Hanwha KEV count zero?
Those vendors publish camera CVEs, and those rows are in the table. CISA currently lists none of them as exploited in the wild. That is not a claim they have no vulnerabilities.
How often is it updated?
Monthly, or when CISA adds a camera-shaped row or a vendor publishes a new camera advisory. Catalog version on this build is 2026.08.19.
Holding these closed across a fleet
The operational problem is knowing whether any of these products, or firmware old enough to carry them, is still installed. MentatNOC continuously watches firmware currency and credential posture on every camera, runs campaigns in staged waves with automatic rollback, and records every check and change in an audit log built so entries cannot be rewritten after the fact. It monitors device health, not video. The action set is on platform actions, and the fastest way to see a fleet's posture is a live platform demo.
the list is the easy part
Know which cameras still run firmware that belongs on this list.
Firmware currency, credentials, and change history for every camera, updated as the vendors move.