Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-55863
  • github.com/motioneye-project/motioneye
motionEye: Missing authentication on ActionHandler allows unauthenticated camera action execution 15 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-46488
  • github.com/motioneye-project/motioneye
motionEye: Authentication possible via password hash 15 Sep
  • Fix available
  • Severity - 9.1 (Critical)
PYSEC-2026-2665
  • PyPI/motioneye
motionEye's missing authentication on ActionHandler allows unauthenticated camera action execution 13 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2667
  • PyPI/motioneye
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read 13 Jul
  • Fix available
PYSEC-2026-2666
  • PyPI/motioneye
motionEye's World-Readable Configuration File Exposes Admin Password Hash 13 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2664
  • PyPI/motioneye
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint 13 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1680
  • PyPI/motioneye
motionEye vulnerable to RCE via unsanitized motion config parameter 07 Jul
  • Fix available
  • Severity - 7.2 (High)
PYSEC-2026-681
  • PyPI/motioneye
Unrestricted Upload of File with Dangerous Type in motionEye 02 Jul
  • No fix available
  • Severity - 7.2 (High)
PYSEC-2026-428
  • PyPI/motioneye
motionEye: Authentication possible via password hash 29 Jun
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-32315
  • github.com/motioneye-project/motioneye
motionEye: World-Readable Configuration File Exposes Admin Password Hash 24 Jun
  • Fix available
  • Severity - 5.5 (Medium)
CVE-2026-31978
  • github.com/motioneye-project/motioneye
motionEye: Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint 24 Jun
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-55488
  • github.com/motioneye-project/motioneye
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read 24 Jun
  • Fix available
  • Severity - 7.7 (High)
GHSA-phv5-334h-mxcw
  • PyPI/motioneye
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal 23 Jun
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-qxvg-h7q2-hcxh
  • PyPI/motioneye
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE) 23 Jun
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-j67x-q29f-qcvv
  • PyPI/motioneye
motionEye's missing authentication on ActionHandler allows unauthenticated camera action execution 23 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-rw9q-97r9-8gvh
  • PyPI/motioneye
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read 23 Jun
  • Fix available