CVE-2024-51482PoC

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • Peaked at 3 mentions on most recent observed day (2026-10-06)
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-07: 1Mentions · 2026-05-09: 1Mentions · 2026-10-06: 3PoC Mentioned / Linked · 2026-03-07: 1PoC Mentioned / Linked · 2026-05-09: 1Exploit Tool / Code · 2026-05-09: 1Technical Details · 2026-03-07: 1Technical Details · 2026-05-09: 103-0705-0910-06
Signal classification1 categories
PoC
2100.0%
Referenced assets3 URLs
Full discourse5 posts
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2024-51482 (CVSS: 10) zoneminder CVE-2025-55182 (CVSS: 10) Meta CVE-2026-103956 (CVSS: 10) AWS CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2018-7600 (CVSS: 9.8) n/a ..🧵👇

    110120433
    370 followersView on X
  • Daeras@0xDaeras
    PoC

    Hi 👋 Recently published two CVE PoCs on GitHub: - CVE-2024-51482 → ZoneMinder auth time-based blind SQL injection - CVE-2025-58434 + CVE-2025-59528 → FlowiseAI ATO + RCE chain Available here: https://github.com/0xDaeras ⚠️ For educational and authorized security research only.

    Post summary

    The post announces that PoC code for several CVEs is now available on GitHub, detailing the vulnerability types but making no claims about active exploitation or patches.

    000301.1K
    57 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2024-51482 — ZoneMinder · PoC live ├ CVE-2025-55182 — Meta/React "React2Shell" · PoC live ├ CVE-2026-103956 — AWS Loom · Unauth bypass PoC live ├ CVE-2026-40281 + CVE-2026-42589 (Gotenberg) · Full RCE chain PoC, still unpatched

    1000066
    370 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2024-51482 [CRITICAL/PoC] CVSS: 10 | Vendor: #zoneminder CVE-2024-51482 🔗 https://exploitgrid.net/exploits/76f8d4d9-a747-4ba7-8253-eb2ab9559f16[EXPLOIT

    1000057
    370 followersView on X
  • 1337 Sheets@1337Sheets
    PoC

    Just dropped our CCTV writeup here: https://kzs.me/htb-cctv 📹💥 Dive into the full exploitation chain: 🔹 ZoneMinder SQL Injection (CVE-2024-51482) 🔹 Credential extraction &amp; hash cracking 🔹 SSH foothold via user 'mark' 🔹 motionEye configuration leak &amp; exploitation https://t.co/oueTrI67UO

    Post summary

    The post shares a writeup detailing a ZoneMinder SQL Injection (CVE‑2024‑51482) exploitation chain, providing PoC material via a link, but offers no evidence of live attacks, patches, or tools.

    00000116
    11 followersView on X

Explore more