Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · szuray

szuray

· 4 Critical

Total CVEs

6

Critical

4

Products

95

Search All CVEs →

6

Products (95)

iptv\/h.264 video encoder firmware6 CVEsiptv\/h.265 video encoder firmware6 CVEsuaioe264-1u6 CVEsuaioe265-1u6 CVEsuce264-1-mini6 CVEsuce264-1wb-mini6 CVEsuce264-4-1u6 CVEsuce264-8-1u6 CVEsuhae264-166 CVEsuhae265-1-mini6 CVEsuhae265-1wb-mini6 CVEsuhae265-4-1u6 CVEsuhce264-16 CVEsuhce264-16p326 CVEsuhce264-1p26 CVEsuhce264-1p2-1u6 CVEsuhce264-1s6 CVEsuhce264-1w6 CVEsuhce264-1ws6 CVEsuhce264-4p86 CVEsuhe264-1-4k6 CVEsuhe264-166 CVEsuhe264-16l-3u6 CVEsuhe264-16s-2u6 CVEsuhe264-1l6 CVEsuhe264-1l-4k6 CVEsuhe264-1lw6 CVEsuhe264-1s6 CVEsuhe264-1s-mini6 CVEsuhe264-1w-mini6 CVEsuhe264-1wb-4g6 CVEsuhe264-1wb-mini6 CVEsuhe264-1wbs-2b6 CVEsuhe264-1wbs-mini6 CVEsuhe264-1ws-mini6 CVEsuhe264-2-1u6 CVEsuhe264-46 CVEsuhe264-4-1u6 CVEsuhe264-4l-1u6 CVEsuhe264-86 CVEsuhe264-8-1u6 CVEsuhe264-8l-3u6 CVEsuhe264-8s-2u6 CVEsuhe265-16 CVEsuhe265-1-1u6 CVEsuhe265-1-4k6 CVEsuhe265-1-mini6 CVEsuhe265-16-3u6 CVEsuhe265-16l-3u6 CVEsuhe265-1l6 CVEsuhe265-1lw6 CVEsuhe265-1s-4k6 CVEsuhe265-1s-mini6 CVEsuhe265-1w6 CVEsuhe265-1w-4k6 CVEsuhe265-1w-mini6 CVEsuhe265-1wb-4g6 CVEsuhe265-1wb-mini6 CVEsuhe265-1wbs-mini6 CVEsuhe265-2-1u6 CVEsuhe265-46 CVEsuhe265-4-1u6 CVEsuhe265-4s6 CVEsuhe265-4s-1u6 CVEsuhe265-8-1u6 CVEsuhe265-8l-3u6 CVEsuhe265-8s-1u6 CVEsuhse265-1u6 CVEsuse264-16-3u6 CVEsuse264-1l6 CVEsuse264-1l-1u6 CVEsuse264-1l-mini6 CVEsuse264-1lw6 CVEsuse264-1wb-l6 CVEsuse264-4l-1u6 CVEsuse264-8-1u6 CVEsuse265-1-1u6 CVEsuse265-1-mini6 CVEsuse265-16l-3u6 CVEsuse265-1l6 CVEsuse265-1l-1u6 CVEsuse265-1l-mini6 CVEsuse265-1lw6 CVEsuse265-1w-mini6 CVEsuse265-1wb-4g6 CVEsuse265-1wb-l6 CVEsuse265-1wb-mini6 CVEsuse265-2-1u6 CVEsuse265-4-1u6 CVEsuse265-4l-1u6 CVEsuse265-8-1u6 CVEsuve264-1l6 CVEsuve264-1lw6 CVEsuve265-16 CVEsuve265-1w6 CVEs

Recent Vulnerabilities

View all 6
CVE-2020-24219HIGH 7.5

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.

CVE-2020-24218CRITICAL 9.8

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file.

CVE-2020-24217CRITICAL 9.8

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.

CVE-2020-24216HIGH 7.5

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via its default name such as /0. Unauthenticated attackers can view video streams that are meant to be private.

CVE-2020-24215CRITICAL 9.8

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin password), and uploading a custom firmware update, to ultimately achieve arbitrary code execution.

CVE-2020-24214CRITICAL 9.8

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. The device will not be able to perform its main purpose of video encoding and streaming for up to a minute, until it automatically reboots. Attackers can send malicious requests once a minute, effectively disabling the device.