Vulnerabilities > Zabbix
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-13 | CVE-2023-29452 | Cross-site Scripting vulnerability in Zabbix Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider. | 5.4 |
2023-07-13 | CVE-2023-29454 | Cross-site Scripting vulnerability in Zabbix Frontend Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages. | 5.4 |
2023-07-13 | CVE-2023-29455 | Cross-site Scripting vulnerability in Zabbix Frontend Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. | 6.1 |
2023-07-13 | CVE-2023-29456 | Cross-site Scripting vulnerability in Zabbix Frontend URL validation scheme receives input from a user and then parses it to identify its various components. | 5.4 |
2023-07-13 | CVE-2023-29457 | Cross-site Scripting vulnerability in Zabbix Frontend Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. | 6.1 |
2023-07-13 | CVE-2023-29458 | Improper Validation of Array Index vulnerability in Zabbix 5.0.34/6.0.17/6.4.2 Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. | 7.5 |
2023-07-13 | CVE-2023-29449 | Allocation of Resources Without Limits or Throttling vulnerability in Zabbix JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. | 4.9 |
2023-07-13 | CVE-2023-29450 | Files or Directories Accessible to External Parties vulnerability in Zabbix JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data. | 7.5 |
2022-12-15 | CVE-2022-46768 | Improper Input Validation vulnerability in Zabbix web Service Report Generation and Zabbix-Agent2 Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. | 5.9 |
2022-12-05 | CVE-2022-43516 | A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI) | 9.8 |