Filtered by vendor Zabbix Subscriptions
Filtered by product Zabbix Subscriptions
Total 65 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-11800 3 Debian, Opensuse, Zabbix 4 Debian Linux, Backports Sle, Leap and 1 more 2024-08-04 9.8 Critical
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
CVE-2021-46088 1 Zabbix 1 Zabbix 2024-08-04 7.2 High
Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.
CVE-2021-27927 1 Zabbix 1 Zabbix 2024-08-03 8.8 High
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method. An attacker doesn't have to know Zabbix user login credentials, but has to know the correct Zabbix URL and contact information of an existing user with sufficient privileges.
CVE-2023-32721 1 Zabbix 1 Zabbix 2024-08-02 7.6 High
A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.
CVE-2024-22119 1 Zabbix 1 Zabbix 2024-08-01 5.5 Medium
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.