D View 8
Vendor:
First CVE: Sep 20, 2023 · Active for 2 years
19
Total CVEs
More Total CVEs than 93% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 78% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact D View 8 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 20, 2023
2 years ago
Most Recent CVE
Jan 21, 2026
185 days ago
CVE Severity & Scoring
D View 819 CVEs
58%
37%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (94.7%)
Unknown0 (0.0%)
Required1 (5.3%)
Privileges Required
Low8 (42.1%)
High1 (5.3%)
None10 (52.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5074CRITICAL Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28 | Sep 20, 2023 | 9.8 | 78 | NO | YES |
CVE-2023-32165CRITICAL D-Link D-View TftpReceiveFileHandler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta | May 3, 2024 | 9.8 | 69 | NO | NO |
CVE-2023-44412HIGH D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affec | May 3, 2024 | 8.2 | 68 | NO | NO |
CVE-2023-32166HIGH D-Link D-View uploadFile Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations o | May 3, 2024 | 8.1 | 64 | NO | NO |
CVE-2023-32164HIGH D-Link D-View TftpSendFileThread Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected | May 3, 2024 | 7.5 | 64 | NO | NO |
CVE-2023-32167MEDIUM D-Link D-View uploadMib Directory Traversal Arbitrary File Creation or Deletion Vulnerability. This vulnerability allows remote attackers to create and delete arbitrary files on af | May 3, 2024 | 6.5 | 61 | NO | NO |
CVE-2023-32169CRITICAL D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations | May 3, 2024 | 9.8 | 60 | NO | NO |
CVE-2024-5296CRITICAL D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations | May 23, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-7163CRITICAL A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. This could result in the disclo | Dec 28, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-44414CRITICAL D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affe | May 3, 2024 | 9.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For D View 8
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.2.89 | 1 | 9.8 | 1.7% | 0 | 0 |
| 2.0.1.28 | 5 | 9.2 | 14.9% | 0 | 1 |
| 1.0.2.13 | 5 | 8.8 | 18.3% | 0 | 0 |