CVE-2021-44255High· 7.2▾ MidnightPoC availableUnrestricted Upload of File with Dangerous Type in motionEye
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 39.6 · likelihood 0.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
3.0%
3.0% → 3.1%
1 GitHub repo
motionEye <= 0.42.1 and motioneEyeOS <= 20200606 allow a remote attacker to upload a configuration backup file containing a malicious python pickle file. This is possible when an installation is accessible over the Internet and uses no or poor authentication credentials.
The GitHub repositories for motionEye and motionEyeOS are no longer being actively maintained as of January 2022, so release of a patched version is unlikely. Keeping a motionEye or motionEyeOS installation off of the Internet and/or using strong credentials provide protection against this issue.
motioneye <= 0.42.1Refer to the advisory for the patched release.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-60787High· 7.2motionEye vulnerable to RCE via unsanitized motion config parameter
CVE-2025-47782HighmotionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
CVE-2026-46488Critical· 9.1motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection
CVE-2026-55863Medium· 5.3motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection
CVE-2026-31978Medium· 6.5motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
CVE-2026-32315Medium· 5.5motionEye's World-Readable Configuration File Exposes Admin Password Hash