Known Vulnerabilities for Nextgen Dvr by Castel
Listed below are 4 of the newest known vulnerabilities associated with "Nextgen Dvr" by "Castel".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Castel Nextgen Dvr
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-9059 json | NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST ... | Not Provided | 2026-05-20 | 2026-05-20 |
| CVE-2026-6566 json | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Obj... | Not Provided | 2026-05-20 | 2026-05-20 |
| CVE-2023-37679 json | A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands... | Not Provided | 2023-08-03 | 2026-07-09 |
| CVE-2020-11682 json | Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web... | 6.5 - MEDIUM | 2020-06-04 | 2020-06-10 |
| CVE-2020-11681 json | Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users c... | 8.1 - HIGH | 2020-06-04 | 2020-06-10 |
| CVE-2020-11680 json | Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to ... | 6.5 - MEDIUM | 2020-06-04 | 2021-07-21 |
| CVE-2020-11679 json | Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Ad... | 8.8 - HIGH | 2020-06-04 | 2021-07-21 |
| CVE-2017-20252 json | Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrar... | 8.8 - HIGH | 2026-06-19 | 2026-06-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Castel | Nextgen Dvr | - |