
ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2024-51482 (CVSS: 10) zoneminder CVE-2025-55182 (CVSS: 10) Meta CVE-2026-103956 (CVSS: 10) AWS CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2018-7600 (CVSS: 9.8) n/a ..🧵👇
Exploit discussion active in current signal (3 latest mentions)
Recommended action window: High priority (within 72h)
NVD description
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
STABLE

ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2024-51482 (CVSS: 10) zoneminder CVE-2025-55182 (CVSS: 10) Meta CVE-2026-103956 (CVSS: 10) AWS CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2018-7600 (CVSS: 9.8) n/a ..🧵👇

Hi 👋 Recently published two CVE PoCs on GitHub: - CVE-2024-51482 → ZoneMinder auth time-based blind SQL injection - CVE-2025-58434 + CVE-2025-59528 → FlowiseAI ATO + RCE chain Available here: https://github.com/0xDaeras ⚠️ For educational and authorized security research only.
Post summary
The post announces that PoC code for several CVEs is now available on GitHub, detailing the vulnerability types but making no claims about active exploitation or patches.

💀 CRITICAL Exploits Trending ├ CVE-2024-51482 — ZoneMinder · PoC live ├ CVE-2025-55182 — Meta/React "React2Shell" · PoC live ├ CVE-2026-103956 — AWS Loom · Unauth bypass PoC live ├ CVE-2026-40281 + CVE-2026-42589 (Gotenberg) · Full RCE chain PoC, still unpatched

[EXPLOIT] CVE-2024-51482 [CRITICAL/PoC] CVSS: 10 | Vendor: #zoneminder CVE-2024-51482 🔗 https://exploitgrid.net/exploits/76f8d4d9-a747-4ba7-8253-eb2ab9559f16[EXPLOIT

Just dropped our CCTV writeup here: https://kzs.me/htb-cctv 📹💥 Dive into the full exploitation chain: 🔹 ZoneMinder SQL Injection (CVE-2024-51482) 🔹 Credential extraction & hash cracking 🔹 SSH foothold via user 'mark' 🔹 motionEye configuration leak & exploitation https://t.co/oueTrI67UO
Post summary
The post shares a writeup detailing a ZoneMinder SQL Injection (CVE‑2024‑51482) exploitation chain, providing PoC material via a link, but offers no evidence of live attacks, patches, or tools.