Known Vulnerabilities for products from Zoneminder
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Zoneminder".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-31493 json | RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language fo... | Not Provided | 2024-10-15 | 2026-07-05 |
| CVE-2023-26039 json | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog ... | 8.8 - HIGH | 2023-02-25 | 2023-03-07 |
| CVE-2023-26038 json | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog ... | 6.5 - MEDIUM | 2023-02-25 | 2023-03-07 |
| CVE-2023-26037 json | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog ... | 9.8 - CRITICAL | 2023-02-25 | 2023-03-07 |
| CVE-2023-26036 json | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog ... | 9.8 - CRITICAL | 2023-02-25 | 2023-03-07 |
| CVE-2023-26035 json | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog ... | 9.8 - CRITICAL | 2023-02-25 | 2023-11-14 |
| CVE-2023-26034 json | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog ... | 8.8 - HIGH | 2023-02-25 | 2023-11-07 |
| CVE-2023-26032 json | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog ... | 8.1 - HIGH | 2023-02-25 | 2023-11-07 |
| CVE-2023-25825 json | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog ... | 6.1 - MEDIUM | 2023-02-25 | 2023-11-07 |
| CVE-2022-39291 json | ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject... | 5.4 - MEDIUM | 2022-10-07 | 2023-03-27 |
| CVE-2022-39290 json | ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users ca... | 6.5 - MEDIUM | 2022-10-07 | 2023-03-27 |
| CVE-2022-39289 json | ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exp... | 7.5 - HIGH | 2022-10-07 | 2023-07-14 |
| CVE-2022-39285 json | ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross ... | 5.4 - MEDIUM | 2022-10-07 | 2023-03-27 |
| CVE-2022-30769 json | Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user. | 4.6 - MEDIUM | 2022-11-15 | 2023-11-07 |
| CVE-2022-30768 json | A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the... | 5.4 - MEDIUM | 2022-11-15 | 2023-11-07 |
| CVE-2022-29806 json | ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbi... | 9.8 - CRITICAL | 2022-04-26 | 2022-05-06 |
| CVE-2020-25729 json | ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php. | 6.1 - MEDIUM | 2020-09-17 | 2020-09-24 |
| CVE-2019-13072 json | Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code... | 5.4 - MEDIUM | 2019-06-30 | 2023-01-30 |
| CVE-2019-8429 json | ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter. | 9.8 - CRITICAL | 2019-02-18 | 2019-02-19 |
| CVE-2019-8428 json | ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a n... | 9.8 - CRITICAL | 2019-02-18 | 2019-02-19 |
Known software with vulnerabilities from Zoneminder
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Zoneminder | Zoneminder | 1.25 |