CVE-2026-102297
- EPSS 0.22%
- Veröffentlicht 28.09.2026 22:17:32
- Zuletzt bearbeitet 30.09.2026 17:23:08
ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, dis...
CVE-2026-102296
- EPSS 0.37%
- Veröffentlicht 28.09.2026 22:17:32
- Zuletzt bearbeitet 30.09.2026 17:23:08
ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers. Attackers ca...
CVE-2024-58386
- EPSS 0.37%
- Veröffentlicht 28.09.2026 22:17:29
- Zuletzt bearbeitet 30.09.2026 17:23:08
ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter is not properly validated before being passed to output_file, enabling attac...
CVE-2026-54258
- EPSS -
- Veröffentlicht 11.09.2026 21:31:30
- Zuletzt bearbeitet 30.09.2026 17:51:56
ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetc...
CVE-2026-76060
- EPSS 2.32%
- Veröffentlicht 27.08.2026 20:29:05
- Zuletzt bearbeitet 31.08.2026 19:18:40
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with Vi...
CVE-2026-72556
- EPSS 0.67%
- Veröffentlicht 11.08.2026 11:11:40
- Zuletzt bearbeitet 03.09.2026 17:51:18
A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The canEdit() and canDelete() methods invoke nonexistent methods on the ZM\U...
CVE-2026-27470
- EPSS 0.48%
- Veröffentlicht 21.02.2026 08:05:01
- Zuletzt bearbeitet 24.02.2026 14:48:36
ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the web/ajax/status.php file within the getNearEvents()...
CVE-2025-65791
- EPSS 1.65%
- Veröffentlicht 18.02.2026 00:00:00
- Zuletzt bearbeitet 11.03.2026 04:17:33
ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function. NOTE: this is disputed by the Supplier because there is no unsanitized user input to web/vie...
CVE-2024-51482
- EPSS 34.98%
- Veröffentlicht 31.10.2024 18:15:05
- Zuletzt bearbeitet 15.04.2026 00:35:42
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.
CVE-2023-31493
- EPSS 0.49%
- Veröffentlicht 15.10.2024 15:15:12
- Zuletzt bearbeitet 05.07.2026 01:18:30
RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.