Search CVE reports
21 – 30 of 85 results
CVE-2022-39285
Medium priorityZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerability (XSS) by backing out of the current "tr" "td" brackets. This then allows a...
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Needs evaluation | Needs evaluation | Needs evaluation | Not in release | Needs evaluation |
CVE-2022-1726
Medium priorityBootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data,...
2 affected packages
netdata, zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
netdata | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
zoneminder | Needs evaluation | Needs evaluation | Needs evaluation | — | Needs evaluation |
CVE-2022-29806
High prioritySome fixes available 3 of 4
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Not affected | Fixed | Fixed | Not in release | Fixed |
CVE-2021-23472
Medium priorityThis affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if...
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Needs evaluation | Needs evaluation | Needs evaluation | — | Needs evaluation |
CVE-2020-25729
Low priorityZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | — | Not affected | Not affected | Not in release | Not affected |
CVE-2019-13072
Medium priorityStored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Vulnerable | Vulnerable | Vulnerable | Not in release | Vulnerable |
CVE-2019-8429
Medium priorityZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Vulnerable | Vulnerable | Vulnerable | Not in release | Not affected |
CVE-2019-8428
Medium priorityZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Vulnerable | Vulnerable | Vulnerable | Not in release | Vulnerable |
CVE-2019-8427
Medium prioritydaemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Not affected | Not affected | Not affected | Not in release | Vulnerable |
CVE-2019-8426
Medium priorityskins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Vulnerable | Vulnerable | Vulnerable | Not in release | Vulnerable |