Vulnerabilities > Zabbix

DATE CVE VULNERABILITY TITLE RISK
2023-12-18 CVE-2023-32726 Improper Check for Unusual or Exceptional Conditions vulnerability in Zabbix Zabbix-Agent
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
network
high complexity
zabbix CWE-754
8.1
2023-12-18 CVE-2023-32727 Improper Input Validation vulnerability in Zabbix Server 6.0.22/6.4.7/7.0.0
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
network
low complexity
zabbix CWE-20
7.2
2023-12-18 CVE-2023-32728 Code Injection vulnerability in Zabbix Zabbix-Agent2
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.
network
low complexity
zabbix CWE-94
critical
9.8
2023-10-12 CVE-2023-32721 Cross-site Scripting vulnerability in Zabbix
A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.
network
low complexity
zabbix CWE-79
5.4
2023-10-12 CVE-2023-32722 Out-of-bounds Write vulnerability in Zabbix
The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.
local
low complexity
zabbix CWE-787
7.8
2023-10-12 CVE-2023-32723 Incorrect Permission Assignment for Critical Resource vulnerability in Zabbix
Request to LDAP is sent before user permissions are checked.
network
low complexity
zabbix CWE-732
critical
9.1
2023-10-12 CVE-2023-32724 Incorrect Permission Assignment for Critical Resource vulnerability in Zabbix
Memory pointer is in a property of the Ducktape object.
network
low complexity
zabbix CWE-732
8.8
2023-10-12 CVE-2023-29453 Code Injection vulnerability in Zabbix Zabbix-Agent2 5.0.0/6.0.0/6.4.0
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected.
network
low complexity
zabbix CWE-94
critical
9.8
2023-08-03 CVE-2023-30958 Cross-site Scripting vulnerability in Zabbix Frontend
A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.225.0.
network
low complexity
zabbix CWE-79
6.1
2023-07-13 CVE-2023-29451 Out-of-bounds Write vulnerability in Zabbix
Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.
network
low complexity
zabbix CWE-787
7.5