Vulnerability index

Browse CVEs

80 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zoneminder MEDIUM 6.1
CVE-2019-6777

An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl paramet…

Patch available
Fix from $1,600 2019-01-24
Zoneminder CRITICAL 9.8
CVE-2018-1000832EPSS 6%

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, …

Fix: after 1.32.2
Fix from $2,300 2018-12-20
Zoneminder CRITICAL 9.8
CVE-2018-1000833

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, …

Fix: after 1.32.2
Fix from $2,300 2018-12-20
Zoneminder MEDIUM 6.1
CVE-2017-7203

A Cross-Site Scripting (XSS) was discovered in ZoneMinder before 1.30.2. The vulnerability exists due to insufficient filtration of user-supplied dat…

Patch available
Fix from $1,600 2017-03-21
Zoneminder CRITICAL 9.8
CVE-2016-10204

SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log…

Fix: after 1.30.0
Fix from $2,300 2017-03-03
Zoneminder HIGH 8.8
CVE-2016-10206

Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requ…

Fix: after 1.30.0
Fix from $1,950 2017-03-03
Zoneminder HIGH 7.3
CVE-2016-10205

Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie.

Fix: after 1.30.0
Fix from $1,950 2017-03-03
Zoneminder MEDIUM 6.1
CVE-2016-10201

Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the format…

Fix: after 1.30.0
Fix from $1,600 2017-03-03
Zoneminder MEDIUM 6.1
CVE-2016-10202

Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path i…

Fix: after 1.30.0
Fix from $1,600 2017-03-03
Zoneminder MEDIUM 6.1
CVE-2016-10203

Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the name w…

Fix: after 1.30.0
Fix from $1,600 2017-03-03
Zoneminder HIGH 8.8
CVE-2017-5368

ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote atta…

No fix yet
Fix from $1,950 2017-02-06
Zoneminder MEDIUM 6.1
CVE-2017-5367

Multiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder v1.30 and v1.29, an open-source CCTV server web appl…

No fix yet
Fix from $1,600 2017-02-06
Zoneminder MEDIUM 5.5
CVE-2017-5595

A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being p…

Fix: after 1.30.0
Fix from $1,600 2017-02-06
Zoneminder HIGH 7.5
CVE-2016-10140EPSS 7%

Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29…

Patch available
Fix from $1,950 2017-01-13
Zoneminder HIGH 7.5
CVE-2013-0232EPSS 48%

includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacha…

No fix yet
Fix from $1,950 2013-03-20
Zoneminder MEDIUM 5.0
CVE-2013-0332EPSS 10%

Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in …

Mitigation only
Fix from $1,600 2013-03-20
Zoneminder MEDIUM 5.0
CVE-2008-6755

ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier…

Patch available
Fix from $1,600 2009-04-27
Zoneminder HIGH 10.0
CVE-2008-3882

Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the exec…

Fix: after 1.23.3
Fix from $1,950 2008-09-02
Zoneminder HIGH 7.5
CVE-2008-3880

SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via …

Fix: after 1.23.3
Fix from $1,950 2008-09-02
Zoneminder HIGH 7.5
CVE-2008-1381

ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary comman…

Mitigation only
Fix from $1,950 2008-05-01