Vulnerabilities > Zabbix

DATE CVE VULNERABILITY TITLE RISK
2024-08-12 CVE-2024-22114 Improper Preservation of Permissions vulnerability in Zabbix
User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard.
network
low complexity
zabbix CWE-281
4.3
2024-08-12 CVE-2024-22116 Code Injection vulnerability in Zabbix
An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section.
network
low complexity
zabbix CWE-94
7.2
2024-08-12 CVE-2024-22121 Improper Preservation of Permissions vulnerability in Zabbix
A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.
local
low complexity
zabbix CWE-281
6.1
2024-08-12 CVE-2024-22122 Command Injection vulnerability in Zabbix
Zabbix allows to configure SMS notifications.
network
low complexity
zabbix CWE-77
critical
9.1
2024-08-12 CVE-2024-22123 Code Injection vulnerability in Zabbix
Setting SMS media allows to set GSM modem file.
network
low complexity
zabbix CWE-94
2.7
2024-08-12 CVE-2024-36460 Insufficiently Protected Credentials vulnerability in Zabbix
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
network
low complexity
zabbix CWE-522
8.1
2024-08-12 CVE-2024-36461 Unspecified vulnerability in Zabbix
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
network
low complexity
zabbix
8.8
2024-08-12 CVE-2024-36462 Allocation of Resources Without Limits or Throttling vulnerability in Zabbix 7.0.0
Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls.
network
low complexity
zabbix CWE-770
7.5
2024-02-09 CVE-2024-22119 Cross-site Scripting vulnerability in Zabbix
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.
network
low complexity
zabbix CWE-79
5.4
2023-12-18 CVE-2023-32725 Reliance on Cookies without Validation and Integrity Checking vulnerability in Zabbix Frontend and Zabbix Server
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports.
network
low complexity
zabbix CWE-565
8.8