CVE-2026-31978
- EPSS 0.42%
- Veröffentlicht 24.06.2026 21:16:53
- Zuletzt bearbeitet 25.06.2026 23:17:02
motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to path traversal in the picture and movie API endpoints, suhc as /picture/{id}/preview/...
CVE-2026-32315
- EPSS 2.9%
- Veröffentlicht 24.06.2026 21:16:53
- Zuletzt bearbeitet 25.06.2026 18:56:54
motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with 644 permissions (-rw-r--r--), making it readable b...
CVE-2026-55488
- EPSS 0.62%
- Veröffentlicht 24.06.2026 15:03:26
- Zuletzt bearbeitet 25.06.2026 18:56:54
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an absolute path traversal vulnerability in multiple media file handlers th...
CVE-2025-60787
- EPSS 24.75%
- Veröffentlicht 03.10.2025 00:00:00
- Zuletzt bearbeitet 10.10.2025 16:22:30
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to ac...
CVE-2025-47782
- EPSS 0.41%
- Veröffentlicht 14.05.2025 16:15:29
- Zuletzt bearbeitet 15.04.2026 00:35:42
motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, using a constructed (camera) device path with the `add`/`add_camera` motionEye web API allows an atta...
CVE-2022-25568
- EPSS 6.83%
- Veröffentlicht 24.03.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:52:22
MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.
CVE-2021-44255
- EPSS 2.95%
- Veröffentlicht 31.01.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:40
Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.