Vulnerabilities > Zabbix > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-08-12 | CVE-2024-22116 | Code Injection vulnerability in Zabbix An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. | 7.2 |
2024-08-12 | CVE-2024-36460 | Insufficiently Protected Credentials vulnerability in Zabbix The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text. | 8.1 |
2024-08-12 | CVE-2024-36461 | Unspecified vulnerability in Zabbix Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. | 8.8 |
2024-08-12 | CVE-2024-36462 | Allocation of Resources Without Limits or Throttling vulnerability in Zabbix 7.0.0 Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. | 7.5 |
2023-12-18 | CVE-2023-32725 | Reliance on Cookies without Validation and Integrity Checking vulnerability in Zabbix Frontend and Zabbix Server The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. | 8.8 |
2023-12-18 | CVE-2023-32726 | Improper Check for Unusual or Exceptional Conditions vulnerability in Zabbix Zabbix-Agent The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server. | 8.1 |
2023-12-18 | CVE-2023-32727 | Improper Input Validation vulnerability in Zabbix Server 6.0.22/6.4.7/7.0.0 An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server. | 7.2 |
2023-10-12 | CVE-2023-32722 | Out-of-bounds Write vulnerability in Zabbix The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open. | 7.8 |
2023-10-12 | CVE-2023-32724 | Incorrect Permission Assignment for Critical Resource vulnerability in Zabbix Memory pointer is in a property of the Ducktape object. | 8.8 |
2023-07-13 | CVE-2023-29451 | Out-of-bounds Write vulnerability in Zabbix Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy. | 7.5 |