Filtered by vendor Zabbix
Subscriptions
Filtered by product Zabbix
Subscriptions
Total
65 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2020-11800 | 3 Debian, Opensuse, Zabbix | 4 Debian Linux, Backports Sle, Leap and 1 more | 2024-08-04 | 9.8 Critical |
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code. | ||||
CVE-2021-46088 | 1 Zabbix | 1 Zabbix | 2024-08-04 | 7.2 High |
Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user. | ||||
CVE-2021-27927 | 1 Zabbix | 1 Zabbix | 2024-08-03 | 8.8 High |
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method. An attacker doesn't have to know Zabbix user login credentials, but has to know the correct Zabbix URL and contact information of an existing user with sufficient privileges. | ||||
CVE-2023-32721 | 1 Zabbix | 1 Zabbix | 2024-08-02 | 7.6 High |
A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL. | ||||
CVE-2024-22119 | 1 Zabbix | 1 Zabbix | 2024-08-01 | 5.5 Medium |
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. |