CVE-2024-51482: Zoneminder

Critical severity, CVSS 9.9. EPSS: 36.6% chance of exploitation in the next 30 days.

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.

Affected products

  • Zoneminder Zoneminder: from 1.37.0, before 1.37.65 (fixed in 1.37.65); from 1.37.0, up to and including 1.37.64

Published 2024-10-31. Last modified 2026-06-17.