Vulnerability index

Browse CVEs

80 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zoneminder MEDIUM 6.1
CVE-2019-8426

skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] para…

Fix: 1.32.3+
Fix from $1,600 2019-02-18
Zoneminder HIGH 8.8
CVE-2019-7346

A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button,…

Fix: after 1.32.3
Fix from $1,950 2019-02-04
Zoneminder HIGH 7.5
CVE-2019-7347

A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even af…

Fix: after 1.32.3
Fix from $1,950 2019-02-04
Zoneminder HIGH 7.3
CVE-2019-7350

Session fixation exists in ZoneMinder through 1.32.3, as an attacker can fixate his own session cookies to the next logged-in user, thereby hijacking…

Fix: after 1.32.3
Fix from $1,950 2019-02-04
Zoneminder MEDIUM 6.5
CVE-2019-7351

Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject …

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7340

POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'filt…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7341

Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable …

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7342

POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'filt…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7343

Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable …

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7344

Reflected XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'filter' as it insecurely prin…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7348

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerabl…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7349

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'n…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7352

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validatio…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7325

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUES…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7326

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerabl…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7327

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 's…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7328

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 's…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7329

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the form action on multiple views utilizes $_SERVER['PHP_SELF'] insecure…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7330

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 's…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7331

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (moni…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7332

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'e…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7333

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'E…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7334

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'E…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7335

Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'log' as it insecurely pri…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7336

Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view _monitor_filters.php contains takes in input from the user …

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7338

Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'group' as it insecurely p…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder MEDIUM 6.1
CVE-2019-7339

POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'leve…

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Zoneminder CRITICAL 9.8
CVE-2019-6991

A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an …

Fix: after 1.32.3
Fix from $2,300 2019-01-28
Zoneminder MEDIUM 6.1
CVE-2019-6992

A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript …

Fix: after 1.32.3
Fix from $1,600 2019-01-28
Zoneminder MEDIUM 5.4
CVE-2019-6990

A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code i…

Fix: after 1.32.3
Fix from $1,600 2019-01-28