Vulnerability index

Browse CVEs

80 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zoneminder HIGH 8.8
CVE-2026-27470

ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is …

Fix: 1.36.38 / 1.38.1+
Fix from $1,950 2026-02-21
Zoneminder CRITICAL 9.8
CVE-2025-65791

ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f…

Mitigation only
Fix from $2,300 2026-02-18
Zoneminder MEDIUM 6.6
CVE-2023-31493

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a …

Fix: after 1.36.33
Fix from $1,600 2024-10-15
Zoneminder CRITICAL 9.8
CVE-2024-43360EPSS 6%

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability.…

Fix: 1.36.34 / 1.37.61+
Fix from $2,300 2024-08-12
Zoneminder MEDIUM 6.1
CVE-2024-43358

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the filter v…

Fix: 1.36.34 / 1.37.61+
Fix from $1,600 2024-08-12
Zoneminder MEDIUM 6.1
CVE-2024-43359

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the montager…

Fix: 1.36.34 / 1.37.61+
Fix from $1,600 2024-08-12
Zoneminder MEDIUM 6.5
CVE-2023-41884

ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query …

Fix: 1.36.34+
Fix from $1,600 2024-08-12
Zoneminder HIGH 8.2
CVE-2020-25730

Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, a…

Fix: 1.34.21+
Fix from $1,950 2024-04-04
Zoneminder CRITICAL 9.8
CVE-2023-26035EPSS 80%

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …

Fix: 1.36.33 / 1.37.33+
Fix from $2,300 2023-02-25
Zoneminder CRITICAL 9.8
CVE-2023-26036

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …

Fix: 1.36.33 / 1.37.33+
Fix from $2,300 2023-02-25
Zoneminder CRITICAL 9.8
CVE-2023-26037

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …

Fix: 1.36.33 / 1.37.33+
Fix from $2,300 2023-02-25
Zoneminder HIGH 8.8
CVE-2023-26039

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …

Fix: 1.36.33 / 1.37.33+
Fix from $1,950 2023-02-25
Zoneminder MEDIUM 6.5
CVE-2023-26038

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …

Fix: 1.36.33 / 1.37.33+
Fix from $1,600 2023-02-25
Zoneminder HIGH 8.8
CVE-2023-26034

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …

Fix: 1.36.33 / 1.37.33+
Fix from $1,950 2023-02-25
Zoneminder HIGH 8.1
CVE-2023-26032

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …

Fix: 1.36.33 / 1.37.33+
Fix from $1,950 2023-02-25
Zoneminder MEDIUM 6.1
CVE-2023-25825

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …

Fix: 1.36.33 / 1.37.33+
Fix from $1,600 2023-02-25
Zoneminder MEDIUM 5.4
CVE-2022-30768

A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an …

Mitigation only
Fix from $1,600 2022-11-15
Zoneminder HIGH 7.5
CVE-2022-39289

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log conten…

Fix: 1.37.24+
Fix from $1,950 2022-10-07
Zoneminder MEDIUM 6.5
CVE-2022-39290EPSS 6%

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by mo…

Fix: 1.36.27 / 1.37.24+
Fix from $1,600 2022-10-07
Zoneminder MEDIUM 5.4
CVE-2022-39285

ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerabi…

Fix: 1.36.27 / 1.37.24+
Fix from $1,600 2022-10-07
Zoneminder MEDIUM 5.4
CVE-2022-39291EPSS 5%

ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability whic…

Fix: 1.36.27 / 1.37.24+
Fix from $1,600 2022-10-07
Zoneminder CRITICAL 9.8
CVE-2022-29806EPSS 67%

ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contribut…

Fix: 1.36.13+
Fix from $2,300 2022-04-26
Zoneminder MEDIUM 6.1
CVE-2020-25729

ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.

Fix: 1.34.21+
Fix from $1,600 2020-09-17
Zoneminder MEDIUM 5.4
CVE-2019-13072

Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any u…

Patch available
Fix from $1,600 2019-06-30
Zoneminder CRITICAL 9.8
CVE-2019-8423

ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.

Fix: after 1.32.3
Fix from $2,300 2019-02-18
Zoneminder CRITICAL 9.8
CVE-2019-8424

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.

Fix: 1.32.3+
Fix from $2,300 2019-02-18
Zoneminder CRITICAL 9.8
CVE-2019-8427

daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.

Fix: 1.32.3+
Fix from $2,300 2019-02-18
Zoneminder CRITICAL 9.8
CVE-2019-8428

ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] va…

Fix: 1.32.3+
Fix from $2,300 2019-02-18
Zoneminder CRITICAL 9.8
CVE-2019-8429

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.

Fix: 1.32.3+
Fix from $2,300 2019-02-18
Zoneminder MEDIUM 6.1
CVE-2019-8425

includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.

Fix: 1.32.3+
Fix from $1,600 2019-02-18