Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2023-29453
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, …
Zabbix Agent2
5.0.35 / 6.0.18+
MEDIUM 6.1
CVE-2023-30958
A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed.
…
Frontend
6.225.0+
HIGH 7.5
CVE-2023-29451
Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.
Zabbix
after 6.4.4
HIGH 7.5
CVE-2023-29458
Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack Java…
Zabbix
Mitigation only
MEDIUM 6.1
CVE-2023-29455
Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser…
Frontend
after 5.0.33
MEDIUM 6.1
CVE-2023-29457
Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through …
Frontend
after 6.0.17
MEDIUM 5.4
CVE-2023-29452EPSS 64%
Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Oth…
Zabbix
after 6.0.17
MEDIUM 5.4
CVE-2023-29454
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicat…
Frontend
after 6.0.16
MEDIUM 5.4
CVE-2023-29456
URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL…
Frontend
after 6.4.3
HIGH 7.5
CVE-2023-29450
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix S…
Zabbix
after 6.4.4
MEDIUM 5.9
CVE-2022-46768EPSS 48%
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper v…
Web Service Report Generation
6.0.12 / 6.2.6+
CRITICAL 9.8
CVE-2022-43515
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this w…
Frontend
after 6.2.4
MEDIUM 5.4
CVE-2022-35230
An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be e…
Zabbix
5.0.25+
MEDIUM 5.4
CVE-2022-35229
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can b…
Zabbix
4.0.0 / 5.0.25+
HIGH 7.2
CVE-2021-46088
Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell…
Zabbix
after 5.0.20
CRITICAL 9.8
CVE-2022-23131 KEVEPSS 96%
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a use…
Zabbix
after 5.4.8
CRITICAL 9.8
CVE-2022-22704
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that…
Zabbix Agent2
5.4.9+
HIGH 8.8
CVE-2021-27927
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthent…
Zabbix
after 5.2.3
CRITICAL 9.8
CVE-2013-3738
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote mali…
Zabbix
Patch available
HIGH 8.8
CVE-2013-3628EPSS 67%
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
Zabbix
No fix yet
CRITICAL 9.8
CVE-2013-5743EPSS 80%
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
Zabbix
after 2.1.7
HIGH 7.5
CVE-2013-7484
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
Zabbix
Mitigation only
CRITICAL 9.1
CVE-2019-17382EPSS 54%
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the…
Zabbix
after 4.4
HIGH 8.1
CVE-2017-2824EPSS 26%
An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets ca…
Zabbix
No fix yet
CRITICAL 9.8
CVE-2016-10134EPSS 83%
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids…
Zabbix
after 2.2.13
HIGH 8.1
CVE-2016-4338EPSS 21%
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before …
Zabbix
Patch available
HIGH 7.5
CVE-2014-9450
Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow re…
Zabbix
after 1.8.21
HIGH 7.5
CVE-2013-6824
Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a n…
Zabbix
after 1.8.18
MEDIUM 5.0
CVE-2013-1364
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
Zabbix
after 1.8.15
HIGH 7.5
CVE-2012-3435
SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to exe…
Zabbix
after 1.8.15