frigate records
10 published records for vendor frigate.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-25643Proof of concept | Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escapefrigate · frigate · CWE-78 | Critical9.1 | — | 3.8% | Feb 6, 2026 |
34Monitor | CVE-2026-33124No exploit | Frigate has insecure password change functionalityfrigate · frigate · CWE-287 | High8.6 | — | 0.4% | Mar 20, 2026 |
32Monitor | CVE-2026-33125No exploit | Frigate Broken Access Control: Users assigned the viewer role can delete admin and other low-privileged accountsfrigate · frigate · CWE-285 | High8.1 | — | 0.4% | Mar 20, 2026 |
30Monitor | CVE-2023-45672No exploit | Frigate unsafe deserialization in `load_config_with_no_duplicates` of `frigate/util/builtin.py`frigate · frigate · CWE-502 | High7.5 | — | 1.4% | Oct 30, 2023 |
27Monitor | CVE-2024-32874No exploit | In Frigate, Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Serviceblakeblackshear · frigate · CWE-770 | Medium6.8 | — | 0.8% | May 14, 2024 |
27Monitor | CVE-2023-45670No exploit | Frigate cross-site request forgery in `config_save` and `config_set` request handlersfrigate · frigate · CWE-352 | Medium6.8 | — | 0.4% | Oct 30, 2023 |
26Monitor | CVE-2026-33469No exploit | Authenticated Frigate users can read the full unredacted configuration via `/api/config/rawfrigate · frigate · CWE-863 | Medium6.5 | — | 0.4% | Mar 26, 2026 |
18Monitor | CVE-2023-45671Proof of concept | Frigate reflected XSS through `/<camera_name>` API endpointsfrigate · frigate · CWE-79 | Medium4.7 | — | 1.4% | Oct 30, 2023 |
17Monitor | CVE-2026-33470No exploit | Frigate has cross-camera snapshot disclosure via unrestricted timeline IDs and missing authorization in /api/events/{event_id}/snapshot-clean.webpfrigate · frigate · CWE-862 | Medium4.3 | — | 0.3% | Mar 26, 2026 |
17Monitor | CVE-2026-33126No exploit | Frigate has SSRF vulnerability in /ffprobe endpointfrigate · frigate · CWE-918 | Medium4.3 | — | 0.3% | Mar 20, 2026 |
- CVE-2026-2564337Monitor
Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
CriticalCVSS 9.1Proof of conceptEPSS 4%frigate · frigateFeb 6, 2026
- CVE-2026-3312434Monitor
Frigate has insecure password change functionality
HighCVSS 8.6No exploitEPSS 0%frigate · frigateMar 20, 2026
- CVE-2026-3312532Monitor
Frigate Broken Access Control: Users assigned the viewer role can delete admin and other low-privileged accounts
HighCVSS 8.1No exploitEPSS 0%frigate · frigateMar 20, 2026
- CVE-2023-4567230Monitor
Frigate unsafe deserialization in `load_config_with_no_duplicates` of `frigate/util/builtin.py`
HighCVSS 7.5No exploitEPSS 1%frigate · frigateOct 30, 2023
- CVE-2024-3287427Monitor
In Frigate, Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service
MediumCVSS 6.8No exploitEPSS 1%blakeblackshear · frigateMay 14, 2024
- CVE-2023-4567027Monitor
Frigate cross-site request forgery in `config_save` and `config_set` request handlers
MediumCVSS 6.8No exploitEPSS 0%frigate · frigateOct 30, 2023
- CVE-2026-3346926Monitor
Authenticated Frigate users can read the full unredacted configuration via `/api/config/raw
MediumCVSS 6.5No exploitEPSS 0%frigate · frigateMar 26, 2026
- CVE-2023-4567118Monitor
Frigate reflected XSS through `/<camera_name>` API endpoints
MediumCVSS 4.7Proof of conceptEPSS 1%frigate · frigateOct 30, 2023
- CVE-2026-3347017Monitor
Frigate has cross-camera snapshot disclosure via unrestricted timeline IDs and missing authorization in /api/events/{event_id}/snapshot-clean.webp
MediumCVSS 4.3No exploitEPSS 0%frigate · frigateMar 26, 2026
- CVE-2026-3312617Monitor
Frigate has SSRF vulnerability in /ffprobe endpoint
MediumCVSS 4.3No exploitEPSS 0%frigate · frigateMar 20, 2026