Zlmediakit
Products
1- 6 CVEs
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27488 | Cri | 0.64 | 9.8 | 0.01 | Apr 8, 2024 | Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate… | ||
| CVE-2023-31861 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2023 | ZLMediaKit 4.0 is vulnerable to Directory Traversal. | ||
| CVE-2022-37237 | Hig | 0.49 | 7.5 | 0.01 | Aug 30, 2022 | An attacker can send malicious RTMP requests to make the ZLMediaKit server crash remotely. Affected version is below commit 7d8b212a3c3368bc2f6507cb74664fc419eb9327. | ||
| CVE-2026-35203 | Hig | 0.42 | 7.5 | 0.00 | Apr 6, 2026 | ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fields from the RTP payload based on flag bits in the first byte, without verifying that sufficient data exists in the buffer. A crafted VP9 RTP packet with a… | ||
| CVE-2023-39067 | Med | 0.40 | 6.1 | 0.00 | Sep 11, 2023 | Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a crafted script to the URL. | ||
| CVE-2026-81028 | Med | 0.32 | 4.9 | — | Aug 26, 2026 | ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration loader in server/WebApi.cpp builds each root with File::absolutePath("", item, true); because the… |
- risk 0.64cvss 9.8epss 0.01
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate…
- risk 0.49cvss 7.5epss 0.01
ZLMediaKit 4.0 is vulnerable to Directory Traversal.
- risk 0.49cvss 7.5epss 0.01
An attacker can send malicious RTMP requests to make the ZLMediaKit server crash remotely. Affected version is below commit 7d8b212a3c3368bc2f6507cb74664fc419eb9327.
- risk 0.42cvss 7.5epss 0.00
ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fields from the RTP payload based on flag bits in the first byte, without verifying that sufficient data exists in the buffer. A crafted VP9 RTP packet with a…
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a crafted script to the URL.
- risk 0.32cvss 4.9epss —
ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration loader in server/WebApi.cpp builds each root with File::absolutePath("", item, true); because the…