ZoneMinder kayıtları
zoneminder üreticisine ait 86 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %3,5
- Pre-auth RCE
- 15
- Düzeltme kaydı olan
- %87,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')43
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')13
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-384 Session Fixation3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
86 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
63Bu hafta | CVE-2023-26035Silahlaştırılmış | ZoneMinder vulnerable to Missing Authorizationzoneminder · zoneminder · CWE-862 | Kritik9,8 | — | %80,5 | 24 Şub 2023 |
59Planlayın | CVE-2022-29806Silahlaştırılmış | ZoneMinder before 1.36.13 allows remote code execution via an invalid language.zoneminder · zoneminder · CWE-22 | Kritik9,8 | — | %67,1 | 26 Nis 2022 |
50Planlayın | CVE-2024-51482Kavram kanıtı | Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64zoneminder · zoneminder · CWE-89 | Kritik9,9 | — | %36,6 | 31 Eki 2024 |
44Planlayın | CVE-2013-0232Silahlaştırılmış | includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shelzoneminder · zoneminder | Yüksek7,5 | — | %47,9 | 20 Mar 2013 |
41Planlayın | CVE-2018-1000832İstismar yok | ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidentizoneminder · zoneminder · CWE-502 | Kritik9,8 | — | %6,4 | 20 Ara 2018 |
41Planlayın | CVE-2024-43360Kavram kanıtı | ZoneMinder Time-based SQL Injectionzoneminder · zoneminder · CWE-89 | Kritik9,8 | — | %6,2 | 12 Ağu 2024 |
41Planlayın | CVE-2008-3882İstismar yok | Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1)zoneminder · zoneminder · CWE-94 | Kritik10,0 | — | %3,5 | 2 Eyl 2008 |
40Planlayın | CVE-2019-6991İstismar yok | A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allzoneminder · zoneminder · CWE-787 | Kritik9,8 | — | %3,3 | 28 Oca 2019 |
40Planlayın | CVE-2018-1000833İstismar yok | ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidentizoneminder · zoneminder · CWE-502 | Kritik9,8 | — | %3,2 | 20 Ara 2018 |
40Planlayın | CVE-2019-8427İstismar yok | daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.zoneminder · zoneminder · CWE-78 | Kritik9,8 | — | %2,5 | 17 Şub 2019 |
40Planlayın | CVE-2016-10204Kavram kanıtı | SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameterzoneminder · zoneminder · CWE-89 | Kritik9,8 | — | %2,1 | 3 Mar 2017 |
40Planlayın | CVE-2025-65791Kavram kanıtı | ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php.zoneminder · zoneminder · CWE-78 | Kritik9,8 | — | %1,7 | 18 Şub 2026 |
39İzleyin | CVE-2019-8429İstismar yok | ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.zoneminder · zoneminder · CWE-89 | Kritik9,8 | — | %1,6 | 17 Şub 2019 |
39İzleyin | CVE-2019-8423İstismar yok | ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.zoneminder · zoneminder · CWE-89 | Kritik9,8 | — | %1,6 | 17 Şub 2019 |
39İzleyin | CVE-2019-8428İstismar yok | ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[Monitorzoneminder · zoneminder · CWE-89 | Kritik9,8 | — | %1,6 | 17 Şub 2019 |
39İzleyin | CVE-2019-8424İstismar yok | ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.zoneminder · zoneminder · CWE-89 | Kritik9,8 | — | %1,6 | 17 Şub 2019 |
39İzleyin | CVE-2023-26036İstismar yok | ZoneMinder contains Local File Inclusion vulnerabilityzoneminder · zoneminder · CWE-426 | Kritik9,8 | — | %0,9 | 24 Şub 2023 |
39İzleyin | CVE-2023-26037İstismar yok | ZoneMinder contains SQL Injection via report_event_auditzoneminder · zoneminder · CWE-89 | Kritik9,8 | — | %0,6 | 24 Şub 2023 |
35İzleyin | CVE-2023-26034İstismar yok | ZoneMinder SQL Injectionzoneminder · zoneminder · CWE-89 | Yüksek8,8 | — | %1,6 | 24 Şub 2023 |
35İzleyin | CVE-2023-26039Kavram kanıtı | ZoneMinder vulnerable to OS Command injection in daemonControl() APIzoneminder · zoneminder · CWE-78 | Yüksek8,8 | — | %1,3 | 24 Şub 2023 |
35İzleyin | CVE-2017-5368İstismar yok | ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a rezoneminder · zoneminder · CWE-352 | Yüksek8,8 | — | %1,1 | 6 Şub 2017 |
35İzleyin | CVE-2016-10206İstismar yok | Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of userszoneminder · zoneminder · CWE-352 | Yüksek8,8 | — | %0,7 | 3 Mar 2017 |
35İzleyin | CVE-2019-7346İstismar yok | A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try againzoneminder · zoneminder · CWE-352 | Yüksek8,8 | — | %0,7 | 4 Şub 2019 |
35İzleyin | CVE-2026-27470Kavram kanıtı | ZoneMinder: Second-Order SQL Injection in `getNearEvents()` via Stored Event Name and Cause Fieldszoneminder · zoneminder · CWE-89 | Yüksek8,8 | — | %0,6 | 21 Şub 2026 |
32İzleyin | CVE-2016-10140Kavram kanıtı | Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 zoneminder · zoneminder · CWE-200 | Yüksek7,5 | — | %6,7 | 13 Oca 2017 |
- CVE-2023-2603563Bu hafta
ZoneMinder vulnerable to Missing Authorization
KritikCVSS 9,8SilahlaştırılmışEPSS %80zoneminder · zoneminder24 Şub 2023
- CVE-2022-2980659Planlayın
ZoneMinder before 1.36.13 allows remote code execution via an invalid language.
KritikCVSS 9,8SilahlaştırılmışEPSS %67zoneminder · zoneminder26 Nis 2022
- CVE-2024-5148250Planlayın
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
KritikCVSS 9,9Kavram kanıtıEPSS %37zoneminder · zoneminder31 Eki 2024
- CVE-2013-023244Planlayın
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shel
YüksekCVSS 7,5SilahlaştırılmışEPSS %48zoneminder · zoneminder20 Mar 2013
- CVE-2018-100083241Planlayın
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidenti
KritikCVSS 9,8İstismar yokEPSS %6zoneminder · zoneminder20 Ara 2018
- CVE-2024-4336041Planlayın
ZoneMinder Time-based SQL Injection
KritikCVSS 9,8Kavram kanıtıEPSS %6zoneminder · zoneminder12 Ağu 2024
- CVE-2008-388241Planlayın
Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1)
KritikCVSS 10,0İstismar yokEPSS %3zoneminder · zoneminder2 Eyl 2008
- CVE-2019-699140Planlayın
A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, all
KritikCVSS 9,8İstismar yokEPSS %3zoneminder · zoneminder28 Oca 2019
- CVE-2018-100083340Planlayın
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidenti
KritikCVSS 9,8İstismar yokEPSS %3zoneminder · zoneminder20 Ara 2018
- CVE-2019-842740Planlayın
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
KritikCVSS 9,8İstismar yokEPSS %2zoneminder · zoneminder17 Şub 2019
- CVE-2016-1020440Planlayın
SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter
KritikCVSS 9,8Kavram kanıtıEPSS %2zoneminder · zoneminder3 Mar 2017
- CVE-2025-6579140Planlayın
ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php.
KritikCVSS 9,8Kavram kanıtıEPSS %2zoneminder · zoneminder18 Şub 2026
- CVE-2019-842939İzleyin
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
KritikCVSS 9,8İstismar yokEPSS %2zoneminder · zoneminder17 Şub 2019
- CVE-2019-842339İzleyin
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
KritikCVSS 9,8İstismar yokEPSS %2zoneminder · zoneminder17 Şub 2019
- CVE-2019-842839İzleyin
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[Monitor
KritikCVSS 9,8İstismar yokEPSS %2zoneminder · zoneminder17 Şub 2019
- CVE-2019-842439İzleyin
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
KritikCVSS 9,8İstismar yokEPSS %2zoneminder · zoneminder17 Şub 2019
- CVE-2023-2603639İzleyin
ZoneMinder contains Local File Inclusion vulnerability
KritikCVSS 9,8İstismar yokEPSS %1zoneminder · zoneminder24 Şub 2023
- CVE-2023-2603739İzleyin
ZoneMinder contains SQL Injection via report_event_audit
KritikCVSS 9,8İstismar yokEPSS %1zoneminder · zoneminder24 Şub 2023
- CVE-2023-2603435İzleyin
ZoneMinder SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %2zoneminder · zoneminder24 Şub 2023
- CVE-2023-2603935İzleyin
ZoneMinder vulnerable to OS Command injection in daemonControl() API
YüksekCVSS 8,8Kavram kanıtıEPSS %1zoneminder · zoneminder24 Şub 2023
- CVE-2017-536835İzleyin
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a re
YüksekCVSS 8,8İstismar yokEPSS %1zoneminder · zoneminder6 Şub 2017
- CVE-2016-1020635İzleyin
Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users
YüksekCVSS 8,8İstismar yokEPSS %1zoneminder · zoneminder3 Mar 2017
- CVE-2019-734635İzleyin
A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again
YüksekCVSS 8,8İstismar yokEPSS %1zoneminder · zoneminder4 Şub 2019
- CVE-2026-2747035İzleyin
ZoneMinder: Second-Order SQL Injection in `getNearEvents()` via Stored Event Name and Cause Fields
YüksekCVSS 8,8Kavram kanıtıEPSS %1zoneminder · zoneminder21 Şub 2026
- CVE-2016-1014032İzleyin
Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30
YüksekCVSS 7,5Kavram kanıtıEPSS %7zoneminder · zoneminder13 Oca 2017