Vulnerabilities > Zabbix > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-12 CVE-2024-22116 Code Injection vulnerability in Zabbix
An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section.
network
low complexity
zabbix CWE-94
7.2
2024-08-12 CVE-2024-36460 Insufficiently Protected Credentials vulnerability in Zabbix
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
network
low complexity
zabbix CWE-522
8.1
2024-08-12 CVE-2024-36461 Unspecified vulnerability in Zabbix
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
network
low complexity
zabbix
8.8
2024-08-12 CVE-2024-36462 Allocation of Resources Without Limits or Throttling vulnerability in Zabbix 7.0.0
Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls.
network
low complexity
zabbix CWE-770
7.5
2023-12-18 CVE-2023-32725 Reliance on Cookies without Validation and Integrity Checking vulnerability in Zabbix Frontend and Zabbix Server
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports.
network
low complexity
zabbix CWE-565
8.8
2023-12-18 CVE-2023-32726 Improper Check for Unusual or Exceptional Conditions vulnerability in Zabbix Zabbix-Agent
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
network
high complexity
zabbix CWE-754
8.1
2023-12-18 CVE-2023-32727 Improper Input Validation vulnerability in Zabbix Server 6.0.22/6.4.7/7.0.0
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
network
low complexity
zabbix CWE-20
7.2
2023-10-12 CVE-2023-32722 Out-of-bounds Write vulnerability in Zabbix
The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.
local
low complexity
zabbix CWE-787
7.8
2023-10-12 CVE-2023-32724 Incorrect Permission Assignment for Critical Resource vulnerability in Zabbix
Memory pointer is in a property of the Ducktape object.
network
low complexity
zabbix CWE-732
8.8
2023-07-13 CVE-2023-29451 Out-of-bounds Write vulnerability in Zabbix
Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.
network
low complexity
zabbix CWE-787
7.5