Vulnerabilities > Zabbix > High

DATE CVE VULNERABILITY TITLE RISK
2020-02-17 CVE-2013-3738 Improper Input Validation vulnerability in Zabbix 2.0.6
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
network
low complexity
zabbix CWE-20
7.5
2019-12-11 CVE-2013-5743 SQL Injection vulnerability in Zabbix
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
network
low complexity
zabbix CWE-89
7.5
2019-11-30 CVE-2013-7484 Inadequate Encryption Strength vulnerability in Zabbix 2.0.8/4.4.0
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
network
low complexity
zabbix CWE-326
7.5
2018-02-01 CVE-2014-3005 XXE vulnerability in multiple products
XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
network
low complexity
zabbix fedoraproject CWE-611
7.5
2017-02-17 CVE-2016-10134 SQL Injection vulnerability in Zabbix
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
network
low complexity
zabbix CWE-89
7.5
2015-01-02 CVE-2014-9450 SQL Injection vulnerability in Zabbix
Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow remote attackers to execute arbitrary SQL commands via the (1) itemid or (2) periods parameter.
network
low complexity
zabbix CWE-89
7.5
2013-12-19 CVE-2013-6824 Code Injection vulnerability in Zabbix
Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter.
network
low complexity
zabbix CWE-94
7.5
2012-08-15 CVE-2012-3435 SQL Injection vulnerability in Zabbix
SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
network
low complexity
zabbix CWE-89
7.5
2011-12-02 CVE-2011-4674 SQL Injection vulnerability in Zabbix 1.8.3/1.8.4
SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbitrary SQL commands via the only_hostid parameter.
network
low complexity
zabbix CWE-89
7.5
2011-11-23 CVE-2010-5049 SQL Injection vulnerability in Zabbix
SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the nav_time parameter.
network
low complexity
zabbix CWE-89
7.5