Vulnerabilities (CVE)

Filtered by vendor Zoneminder Subscribe
Total 85 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1000832 1 Zoneminder 1 Zoneminder 2024-11-21 10.0 HIGH 9.8 CRITICAL
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
CVE-2023-41884 1 Zoneminder 1 Zoneminder 2024-09-13 N/A 6.5 MEDIUM
ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34.
CVE-2024-43359 1 Zoneminder 1 Zoneminder 2024-09-04 N/A 6.1 MEDIUM
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the montagereview via the displayinterval, speed, and scale parameters. This vulnerability is fixed in 1.36.34 and 1.37.61.
CVE-2024-43360 1 Zoneminder 1 Zoneminder 2024-09-04 N/A 9.8 CRITICAL
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.
CVE-2024-43358 1 Zoneminder 1 Zoneminder 2024-09-04 N/A 6.1 MEDIUM
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the filter view via the filter[Id]. This vulnerability is fixed in 1.36.34 and 1.37.61.