CVE-2026-67827
- EPSS 0.21%
- Veröffentlicht 21.09.2026 21:17:08
- Zuletzt bearbeitet 24.09.2026 13:17:10
Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap conf...
CVE-2026-81028
- EPSS 0.35%
- Veröffentlicht 26.08.2026 15:44:57
- Zuletzt bearbeitet 23.09.2026 17:17:43
ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration loader in server/WebApi.cpp builds each root with File::absolutePath("", item,...
CVE-2026-35203
- EPSS 0.35%
- Veröffentlicht 06.04.2026 19:54:45
- Zuletzt bearbeitet 24.07.2026 21:10:00
ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fields from the RTP payload based on flag bits in the first byte, without verifying that sufficient data exists in the buffer. A craf...
CVE-2024-27488
- EPSS 0.63%
- Veröffentlicht 08.04.2024 06:15:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret param...
CVE-2023-39067
- EPSS 0.38%
- Veröffentlicht 11.09.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 08:14:42
Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a crafted script to the URL.
CVE-2023-31861
- EPSS 1.14%
- Veröffentlicht 25.05.2023 02:15:08
- Zuletzt bearbeitet 16.01.2025 15:15:10
ZLMediaKit 4.0 is vulnerable to Directory Traversal.
CVE-2022-37237
- EPSS 0.72%
- Veröffentlicht 30.08.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:14:38
An attacker can send malicious RTMP requests to make the ZLMediaKit server crash remotely. Affected version is below commit 7d8b212a3c3368bc2f6507cb74664fc419eb9327.