Zoneminder

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 88
    Known Exploited: 0
    16
    Critical Level Threats
    23
    High Level Threats
    47
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-76060

    OS Command Injection in PayRange API

    Last Modified: Aug 28, 2026
    Published: Aug 27, 2026

    CVE-2026-72556

    ZoneMinder ZoneMinder - Remote Code Execution

    Last Modified: Aug 11, 2026
    Published: Aug 11, 2026

    CVE-2026-27470

    ZoneMinder: Second-Order SQL Injection in `getNearEvents()` via Stored Event Name and Cause Fields

    Last Modified: Apr 17, 2026
    Published: Feb 21, 2026

    CVE-2025-65791

    ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function. NOTE: this is disputed by the Supplier because there is no unsanitized user input to web/views/image.php.

    Last Modified: Mar 11, 2026
    Published: Feb 18, 2026

    CVE-2024-51482

    Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64

    Last Modified: Apr 15, 2026
    Published: Oct 31, 2024
    Items Per Page