Vulnerability index

Browse CVEs

80 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-27470 ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is … Zoneminder 1.36.38 / 1.38.1+ Fix from $1,9502026-02-21 CRITICAL 9.8 CVE-2025-65791 ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f… Zoneminder Mitigation only Fix from $2,3002026-02-18 MEDIUM 6.6 CVE-2023-31493 RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a … Zoneminder after 1.36.33 Fix from $1,6002024-10-15 CRITICAL 9.8 CVE-2024-43360EPSS 6% ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability.… Zoneminder 1.36.34 / 1.37.61+ Fix from $2,3002024-08-12 MEDIUM 6.1 CVE-2024-43358 ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the filter v… Zoneminder 1.36.34 / 1.37.61+ Fix from $1,6002024-08-12 MEDIUM 6.1 CVE-2024-43359 ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the montager… Zoneminder 1.36.34 / 1.37.61+ Fix from $1,6002024-08-12 MEDIUM 6.5 CVE-2023-41884 ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query … Zoneminder 1.36.34+ Fix from $1,6002024-08-12 HIGH 8.2 CVE-2020-25730 Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, a… Zoneminder 1.34.21+ Fix from $1,9502024-04-04 CRITICAL 9.8 CVE-2023-26035EPSS 80% ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior … Zoneminder 1.36.33 / 1.37.33+ Fix from $2,3002023-02-25 CRITICAL 9.8 CVE-2023-26036 ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior … Zoneminder 1.36.33 / 1.37.33+ Fix from $2,3002023-02-25 CRITICAL 9.8 CVE-2023-26037 ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior … Zoneminder 1.36.33 / 1.37.33+ Fix from $2,3002023-02-25 HIGH 8.8 CVE-2023-26039 ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior … Zoneminder 1.36.33 / 1.37.33+ Fix from $1,9502023-02-25 MEDIUM 6.5 CVE-2023-26038 ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior … Zoneminder 1.36.33 / 1.37.33+ Fix from $1,6002023-02-25 HIGH 8.8 CVE-2023-26034 ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior … Zoneminder 1.36.33 / 1.37.33+ Fix from $1,9502023-02-25 HIGH 8.1 CVE-2023-26032 ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior … Zoneminder 1.36.33 / 1.37.33+ Fix from $1,9502023-02-25 MEDIUM 6.1 CVE-2023-25825 ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior … Zoneminder 1.36.33 / 1.37.33+ Fix from $1,6002023-02-25 MEDIUM 5.4 CVE-2022-30768 A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an … Zoneminder Mitigation only Fix from $1,6002022-11-15 HIGH 7.5 CVE-2022-39289 ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log conten… Zoneminder 1.37.24+ Fix from $1,9502022-10-07 MEDIUM 6.5 CVE-2022-39290EPSS 6% ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by mo… Zoneminder 1.36.27 / 1.37.24+ Fix from $1,6002022-10-07 MEDIUM 5.4 CVE-2022-39285 ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerabi… Zoneminder 1.36.27 / 1.37.24+ Fix from $1,6002022-10-07 MEDIUM 5.4 CVE-2022-39291EPSS 5% ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability whic… Zoneminder 1.36.27 / 1.37.24+ Fix from $1,6002022-10-07 CRITICAL 9.8 CVE-2022-29806EPSS 67% ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contribut… Zoneminder 1.36.13+ Fix from $2,3002022-04-26 MEDIUM 6.1 CVE-2020-25729 ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php. Zoneminder 1.34.21+ Fix from $1,6002020-09-17 MEDIUM 5.4 CVE-2019-13072 Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any u… Zoneminder Patch available Fix from $1,6002019-06-30 CRITICAL 9.8 CVE-2019-8423 ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter. Zoneminder after 1.32.3 Fix from $2,3002019-02-18 CRITICAL 9.8 CVE-2019-8424 ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter. Zoneminder 1.32.3+ Fix from $2,3002019-02-18 CRITICAL 9.8 CVE-2019-8427 daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters. Zoneminder 1.32.3+ Fix from $2,3002019-02-18 CRITICAL 9.8 CVE-2019-8428 ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] va… Zoneminder 1.32.3+ Fix from $2,3002019-02-18 CRITICAL 9.8 CVE-2019-8429 ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter. Zoneminder 1.32.3+ Fix from $2,3002019-02-18 MEDIUM 6.1 CVE-2019-8425 includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages. Zoneminder 1.32.3+ Fix from $1,6002019-02-18