Skip to content
Noroxi

frigate records

10 published records for vendor frigate.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
40%
Median publish → KEV
No record has entered KEV

All records

10 records
  • Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape

    CriticalCVSS 9.1Proof of conceptEPSS 4%

    frigate · frigateFeb 6, 2026

  • Frigate has insecure password change functionality

    HighCVSS 8.6No exploitEPSS 0%

    frigate · frigateMar 20, 2026

  • Frigate Broken Access Control: Users assigned the viewer role can delete admin and other low-privileged accounts

    HighCVSS 8.1No exploitEPSS 0%

    frigate · frigateMar 20, 2026

  • Frigate unsafe deserialization in `load_config_with_no_duplicates` of `frigate/util/builtin.py`

    HighCVSS 7.5No exploitEPSS 1%

    frigate · frigateOct 30, 2023

  • In Frigate, Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service

    MediumCVSS 6.8No exploitEPSS 1%

    blakeblackshear · frigateMay 14, 2024

  • Frigate cross-site request forgery in `config_save` and `config_set` request handlers

    MediumCVSS 6.8No exploitEPSS 0%

    frigate · frigateOct 30, 2023

  • Authenticated Frigate users can read the full unredacted configuration via `/api/config/raw

    MediumCVSS 6.5No exploitEPSS 0%

    frigate · frigateMar 26, 2026

  • Frigate reflected XSS through `/<camera_name>` API endpoints

    MediumCVSS 4.7Proof of conceptEPSS 1%

    frigate · frigateOct 30, 2023

  • Frigate has cross-camera snapshot disclosure via unrestricted timeline IDs and missing authorization in /api/events/{event_id}/snapshot-clean.webp

    MediumCVSS 4.3No exploitEPSS 0%

    frigate · frigateMar 26, 2026

  • Frigate has SSRF vulnerability in /ffprobe endpoint

    MediumCVSS 4.3No exploitEPSS 0%

    frigate · frigateMar 20, 2026