ispyconnect records
6 published records for vendor ispyconnect.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-287 Improper Authentication1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2022-29775Proof of concept | iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.ispyconnect · ispy · CWE-287 | Critical9.8 | — | 60.3% | Jun 21, 2022 |
41Plan | CVE-2022-29774No exploit | iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.ispyconnect · ispy · CWE-22 | Critical9.8 | — | 5.6% | Jun 21, 2022 |
35Monitor | CVE-2024-22514Proof of concept | An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.ispyconnect · agent dvr · CWE-22 | High8.8 | — | 1.4% | Feb 6, 2024 |
35Monitor | CVE-2024-22515Proof of concept | Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio ispyconnect · agent dvr · CWE-434 | High8.8 | — | 1.2% | Feb 6, 2024 |
31Monitor | CVE-2025-63408Proof of concept | Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to ispyconnect · agent dvr · CWE-22 | High7.8 | — | 0.4% | Nov 18, 2025 |
21Monitor | CVE-2020-13093No exploit | iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.ispyconnect · agent dvr · CWE-22 | Medium5.3 | — | 1.3% | May 15, 2020 |
- CVE-2022-2977557Plan
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
CriticalCVSS 9.8Proof of conceptEPSS 60%ispyconnect · ispyJun 21, 2022
- CVE-2022-2977441Plan
iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.
CriticalCVSS 9.8No exploitEPSS 6%ispyconnect · ispyJun 21, 2022
- CVE-2024-2251435Monitor
An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.
HighCVSS 8.8Proof of conceptEPSS 1%ispyconnect · agent dvrFeb 6, 2024
- CVE-2024-2251535Monitor
Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio
HighCVSS 8.8Proof of conceptEPSS 1%ispyconnect · agent dvrFeb 6, 2024
- CVE-2025-6340831Monitor
Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to
HighCVSS 7.8Proof of conceptEPSS 0%ispyconnect · agent dvrNov 18, 2025
- CVE-2020-1309321Monitor
iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.
MediumCVSS 5.3No exploitEPSS 1%ispyconnect · agent dvrMay 15, 2020