Vulnerabilities > Zabbix > Zabbix Agent2 > 5.4.0

DATE CVE VULNERABILITY TITLE RISK
2022-12-15 CVE-2022-46768 Improper Input Validation vulnerability in Zabbix web Service Report Generation and Zabbix-Agent2
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053.
network
high complexity
zabbix CWE-20
5.9
2022-01-06 CVE-2022-22704 Missing Initialization of Resource vulnerability in Zabbix Zabbix-Agent2
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.
network
low complexity
zabbix CWE-909
critical
9.8