Vulnerability index

Browse CVEs

74 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zabbix Agent2 CRITICAL 9.8
CVE-2023-29453

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, …

Fix: 5.0.35 / 6.0.18+
Fix from $2,300 2023-10-12
Frontend MEDIUM 6.1
CVE-2023-30958

A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. …

Fix: 6.225.0+
Fix from $1,600 2023-08-03
Zabbix HIGH 7.5
CVE-2023-29451

Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.

Fix: after 6.4.4
Fix from $1,950 2023-07-13
Zabbix HIGH 7.5
CVE-2023-29458

Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack Java…

Mitigation only
Fix from $1,950 2023-07-13
Frontend MEDIUM 6.1
CVE-2023-29455

Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser…

Fix: after 5.0.33
Fix from $1,600 2023-07-13
Frontend MEDIUM 6.1
CVE-2023-29457

Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through …

Fix: after 6.0.17
Fix from $1,600 2023-07-13
Zabbix MEDIUM 5.4
CVE-2023-29452EPSS 64%

Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Oth…

Fix: after 6.0.17
Fix from $1,600 2023-07-13
Frontend MEDIUM 5.4
CVE-2023-29454

Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicat…

Fix: after 6.0.16
Fix from $1,600 2023-07-13
Frontend MEDIUM 5.4
CVE-2023-29456

URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL…

Fix: after 6.4.3
Fix from $1,600 2023-07-13
Zabbix HIGH 7.5
CVE-2023-29450

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix S…

Fix: after 6.4.4
Fix from $1,950 2023-07-13
Web Service Report Generation MEDIUM 5.9
CVE-2022-46768EPSS 48%

Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper v…

Fix: 6.0.12 / 6.2.6+
Fix from $1,600 2022-12-15
Frontend CRITICAL 9.8
CVE-2022-43515

Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this w…

Fix: after 6.2.4
Fix from $2,300 2022-12-05
Zabbix MEDIUM 5.4
CVE-2022-35230

An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be e…

Fix: 5.0.25+
Fix from $1,600 2022-07-06
Zabbix MEDIUM 5.4
CVE-2022-35229

An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can b…

Fix: 4.0.0 / 5.0.25+
Fix from $1,600 2022-07-06
Zabbix HIGH 7.2
CVE-2021-46088

Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell…

Fix: after 5.0.20
Fix from $1,950 2022-01-27
Zabbix CRITICAL 9.8
CVE-2022-23131 KEVEPSS 96%

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a use…

Fix: after 5.4.8
Fix from $2,300 2022-01-13
Zabbix Agent2 CRITICAL 9.8
CVE-2022-22704

The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that…

Fix: 5.4.9+
Fix from $2,300 2022-01-06
Zabbix HIGH 8.8
CVE-2021-27927

In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthent…

Fix: after 5.2.3
Fix from $1,950 2021-03-03
Zabbix CRITICAL 9.8
CVE-2013-3738

A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote mali…

Patch available
Fix from $2,300 2020-02-17
Zabbix HIGH 8.8
CVE-2013-3628EPSS 67%

Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

No fix yet
Fix from $1,950 2020-02-07
Zabbix CRITICAL 9.8
CVE-2013-5743EPSS 80%

Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

Fix: after 2.1.7
Fix from $2,300 2019-12-11
Zabbix HIGH 7.5
CVE-2013-7484

Zabbix before 5.0 represents passwords in the users table with unsalted MD5.

Mitigation only
Fix from $1,950 2019-11-30
Zabbix CRITICAL 9.1
CVE-2019-17382EPSS 54%

An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the…

Fix: after 4.4
Fix from $2,300 2019-10-09
Zabbix HIGH 8.1
CVE-2017-2824EPSS 26%

An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets ca…

No fix yet
Fix from $1,950 2017-05-24
Zabbix CRITICAL 9.8
CVE-2016-10134EPSS 83%

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids…

Fix: after 2.2.13
Fix from $2,300 2017-02-17
Zabbix HIGH 8.1
CVE-2016-4338EPSS 21%

The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before …

Patch available
Fix from $1,950 2017-01-23
Zabbix HIGH 7.5
CVE-2014-9450

Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow re…

Fix: after 1.8.21
Fix from $1,950 2015-01-02
Zabbix HIGH 7.5
CVE-2013-6824

Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a n…

Fix: after 1.8.18
Fix from $1,950 2013-12-19
Zabbix MEDIUM 5.0
CVE-2013-1364

The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.

Fix: after 1.8.15
Fix from $1,600 2013-12-14
Zabbix HIGH 7.5
CVE-2012-3435

SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to exe…

Fix: after 1.8.15
Fix from $1,950 2012-08-15