Vulnerability index

Browse CVEs

74 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-29453 Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, … Zabbix Agent2 5.0.35 / 6.0.18+ Fix from $2,3002023-10-12 MEDIUM 6.1 CVE-2023-30958 A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. … Frontend 6.225.0+ Fix from $1,6002023-08-03 HIGH 7.5 CVE-2023-29451 Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy. Zabbix after 6.4.4 Fix from $1,9502023-07-13 HIGH 7.5 CVE-2023-29458 Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack Java… Zabbix Mitigation only Fix from $1,9502023-07-13 MEDIUM 6.1 CVE-2023-29455 Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser… Frontend after 5.0.33 Fix from $1,6002023-07-13 MEDIUM 6.1 CVE-2023-29457 Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through … Frontend after 6.0.17 Fix from $1,6002023-07-13 MEDIUM 5.4 CVE-2023-29452EPSS 64% Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Oth… Zabbix after 6.0.17 Fix from $1,6002023-07-13 MEDIUM 5.4 CVE-2023-29454 Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicat… Frontend after 6.0.16 Fix from $1,6002023-07-13 MEDIUM 5.4 CVE-2023-29456 URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL… Frontend after 6.4.3 Fix from $1,6002023-07-13 HIGH 7.5 CVE-2023-29450 JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix S… Zabbix after 6.4.4 Fix from $1,9502023-07-13 MEDIUM 5.9 CVE-2022-46768EPSS 48% Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper v… Web Service Report Generation 6.0.12 / 6.2.6+ Fix from $1,6002022-12-15 CRITICAL 9.8 CVE-2022-43515 Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this w… Frontend after 6.2.4 Fix from $2,3002022-12-05 MEDIUM 5.4 CVE-2022-35230 An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be e… Zabbix 5.0.25+ Fix from $1,6002022-07-06 MEDIUM 5.4 CVE-2022-35229 An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can b… Zabbix 4.0.0 / 5.0.25+ Fix from $1,6002022-07-06 HIGH 7.2 CVE-2021-46088 Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell… Zabbix after 5.0.20 Fix from $1,9502022-01-27 CRITICAL 9.8 CVE-2022-23131 KEVEPSS 96% In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a use… Zabbix after 5.4.8 Fix from $2,3002022-01-13 CRITICAL 9.8 CVE-2022-22704 The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that… Zabbix Agent2 5.4.9+ Fix from $2,3002022-01-06 HIGH 8.8 CVE-2021-27927 In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthent… Zabbix after 5.2.3 Fix from $1,9502021-03-03 CRITICAL 9.8 CVE-2013-3738 A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote mali… Zabbix Patch available Fix from $2,3002020-02-17 HIGH 8.8 CVE-2013-3628EPSS 67% Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability Zabbix No fix yet Fix from $1,9502020-02-07 CRITICAL 9.8 CVE-2013-5743EPSS 80% Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7. Zabbix after 2.1.7 Fix from $2,3002019-12-11 HIGH 7.5 CVE-2013-7484 Zabbix before 5.0 represents passwords in the users table with unsalted MD5. Zabbix Mitigation only Fix from $1,9502019-11-30 CRITICAL 9.1 CVE-2019-17382EPSS 54% An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the… Zabbix after 4.4 Fix from $2,3002019-10-09 HIGH 8.1 CVE-2017-2824EPSS 26% An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets ca… Zabbix No fix yet Fix from $1,9502017-05-24 CRITICAL 9.8 CVE-2016-10134EPSS 83% SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids… Zabbix after 2.2.13 Fix from $2,3002017-02-17 HIGH 8.1 CVE-2016-4338EPSS 21% The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before … Zabbix Patch available Fix from $1,9502017-01-23 HIGH 7.5 CVE-2014-9450 Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow re… Zabbix after 1.8.21 Fix from $1,9502015-01-02 HIGH 7.5 CVE-2013-6824 Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a n… Zabbix after 1.8.18 Fix from $1,9502013-12-19 MEDIUM 5.0 CVE-2013-1364 The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter. Zabbix after 1.8.15 Fix from $1,6002013-12-14 HIGH 7.5 CVE-2012-3435 SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to exe… Zabbix after 1.8.15 Fix from $1,9502012-08-15