Vulnerability index

Browse CVEs

80 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2019-6777 An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl paramet… Zoneminder Patch available Fix from $1,6002019-01-24 CRITICAL 9.8 CVE-2018-1000832EPSS 6% ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, … Zoneminder after 1.32.2 Fix from $2,3002018-12-20 CRITICAL 9.8 CVE-2018-1000833 ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, … Zoneminder after 1.32.2 Fix from $2,3002018-12-20 MEDIUM 6.1 CVE-2017-7203 A Cross-Site Scripting (XSS) was discovered in ZoneMinder before 1.30.2. The vulnerability exists due to insufficient filtration of user-supplied dat… Zoneminder Patch available Fix from $1,6002017-03-21 CRITICAL 9.8 CVE-2016-10204 SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log… Zoneminder after 1.30.0 Fix from $2,3002017-03-03 HIGH 8.8 CVE-2016-10206 Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requ… Zoneminder after 1.30.0 Fix from $1,9502017-03-03 HIGH 7.3 CVE-2016-10205 Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie. Zoneminder after 1.30.0 Fix from $1,9502017-03-03 MEDIUM 6.1 CVE-2016-10201 Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the format… Zoneminder after 1.30.0 Fix from $1,6002017-03-03 MEDIUM 6.1 CVE-2016-10202 Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path i… Zoneminder after 1.30.0 Fix from $1,6002017-03-03 MEDIUM 6.1 CVE-2016-10203 Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the name w… Zoneminder after 1.30.0 Fix from $1,6002017-03-03 HIGH 8.8 CVE-2017-5368 ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote atta… Zoneminder No fix yet Fix from $1,9502017-02-06 MEDIUM 6.1 CVE-2017-5367 Multiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder v1.30 and v1.29, an open-source CCTV server web appl… Zoneminder No fix yet Fix from $1,6002017-02-06 MEDIUM 5.5 CVE-2017-5595 A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being p… Zoneminder after 1.30.0 Fix from $1,6002017-02-06 HIGH 7.5 CVE-2016-10140EPSS 7% Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29… Zoneminder Patch available Fix from $1,9502017-01-13 HIGH 7.5 CVE-2013-0232EPSS 48% includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacha… Zoneminder No fix yet Fix from $1,9502013-03-20 MEDIUM 5.0 CVE-2013-0332EPSS 10% Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in … Zoneminder Mitigation only Fix from $1,6002013-03-20 MEDIUM 5.0 CVE-2008-6755 ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier… Zoneminder Patch available Fix from $1,6002009-04-27 HIGH 10.0 CVE-2008-3882 Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the exec… Zoneminder after 1.23.3 Fix from $1,9502008-09-02 HIGH 7.5 CVE-2008-3880 SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via … Zoneminder after 1.23.3 Fix from $1,9502008-09-02 HIGH 7.5 CVE-2008-1381 ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary comman… Zoneminder Mitigation only Fix from $1,9502008-05-01