VulnSea

motioneye vulnerabilities

CVEs whose affected-version data names the motioneye package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-46488Critical· 9.1PoC
1w ago

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash c…

Abyssalmotioneye-project · motioneyeEPSS 0.27%via NVD
CVE-2026-55863Medium· 5.3PoC
1w ago

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, the ActionHandler.post() method in motioneye/handlers/action.py lacks the Base…

Twilightmotioneye-project · motioneyeEPSS 0.29%via NVD
CVE-2026-55488High
3mo ago

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

Twilightmotioneye · motioneyeEPSS 0.62%via GHSA
GHSA-qxvg-h7q2-hcxhCritical· 9.8
3mo ago

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

Midnightmotioneye · motioneyevia GHSA
GHSA-phv5-334h-mxcwCritical
3mo ago

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

Midnightmotioneye · motioneyevia GHSA
CVE-2026-31978Medium· 6.5
3mo ago

motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint

motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint

Sunlitmotioneye · motioneyeEPSS 0.42%via GHSA
CVE-2026-32315Medium· 5.5
3mo ago

motionEye's World-Readable Configuration File Exposes Admin Password Hash

motionEye's World-Readable Configuration File Exposes Admin Password Hash

Sunlitmotioneye · motioneyeEPSS 2.9%via GHSA
CVE-2025-60787High· 7.2PoC
10mo ago

motionEye vulnerable to RCE via unsanitized motion config parameter

motionEye vulnerable to RCE via unsanitized motion config parameter

Midnightmotioneye · motioneyeEPSS 18%via OSV
CVE-2025-47782High
1y ago

motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution

motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution

Twilightmotioneye · motioneyeEPSS 0.49%via OSV
CVE-2021-44255High· 7.2PoC
4y ago

Unrestricted Upload of File with Dangerous Type in motionEye

Unrestricted Upload of File with Dangerous Type in motionEye

Midnightmotioneye · motioneyeEPSS 3.1%via OSV
motioneye vulnerabilities (CVEs) · VulnSea