Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zabbix zabbix 1.8 vulnerabilities and exploits
(subscribe to this query)
755
VMScore
CVE-2013-5743
Multiple SQL injection vulnerabilities in Zabbix 1.8.x prior to 1.8.18rc1, 2.0.x prior to 2.0.9rc1, and 2.1.x prior to 2.1.7.
Zabbix Zabbix
1 EDB exploit
755
VMScore
CVE-2012-3435
SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and previous versions, and 2.x prior to 2.0.2rc1, allows remote malicious users to execute arbitrary SQL commands via the itemid parameter.
Zabbix Zabbix
Zabbix Zabbix 1.7.4
Zabbix Zabbix 1.1
Zabbix Zabbix 1.1.6
Zabbix Zabbix 1.1.7
Zabbix Zabbix 1.4.6
Zabbix Zabbix 1.8.2
Zabbix Zabbix 1.1.3
Zabbix Zabbix 1.8.3
Zabbix Zabbix 1.4.5
Zabbix Zabbix 1.5.2
Zabbix Zabbix 1.5.1
Zabbix Zabbix 1.7.1
Zabbix Zabbix 1.6.8
Zabbix Zabbix 1.3
Zabbix Zabbix 1.3.1
Zabbix Zabbix 1.1.2
Zabbix Zabbix 1.8
Zabbix Zabbix 1.8.1
Zabbix Zabbix 1.3.8
Zabbix Zabbix 1.5
Zabbix Zabbix 1.6.2
1 EDB exploit
690
VMScore
CVE-2009-4498
The node_process_command function in Zabbix Server prior to 1.8 allows remote malicious users to execute arbitrary commands via a crafted request.
Zabbix Zabbix 1.1.2
Zabbix Zabbix 1.6.6
Zabbix Zabbix 1.7
Zabbix Zabbix 1.1.4
Zabbix Zabbix 1.1.3
Zabbix Zabbix 1.7.2
Zabbix Zabbix 1.7.1
Zabbix Zabbix 1.4.2
Zabbix Zabbix 1.1.5
Zabbix Zabbix
Zabbix Zabbix 1.7.3
Zabbix Zabbix 1.4.3
Zabbix Zabbix 1.6.7
Zabbix Zabbix 1.6.8
2 EDB exploits
668
VMScore
CVE-2014-3005
XML external entity (XXE) vulnerability in Zabbix 1.8.x prior to 1.8.21rc1, 2.0.x prior to 2.0.13rc1, 2.2.x prior to 2.2.5rc1, and 2.3.x prior to 2.3.2 allows remote malicious users to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
Zabbix Zabbix 2.2.1
Zabbix Zabbix 2.2.3
Zabbix Zabbix 2.0.5
Zabbix Zabbix 2.0.7
Zabbix Zabbix 2.0.12
Zabbix Zabbix 1.8.1
Zabbix Zabbix 1.8.8
Zabbix Zabbix 1.8.10
Zabbix Zabbix 1.8.17
Zabbix Zabbix 1.8.19
Zabbix Zabbix 2.3.0
Zabbix Zabbix 2.3.1
Zabbix Zabbix 2.2.0
Zabbix Zabbix 2.0.8
Zabbix Zabbix 2.0.9
Zabbix Zabbix 2.0.10
Zabbix Zabbix 2.0.11
Zabbix Zabbix 1.8.12
Zabbix Zabbix 1.8.13
Zabbix Zabbix 1.8.14
Zabbix Zabbix 1.8.15
Zabbix Zabbix 2.0.0
668
VMScore
CVE-2010-5049
SQL injection vulnerability in events.php in Zabbix 1.8.1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the nav_time parameter.
Zabbix Zabbix 1.7.2
Zabbix Zabbix 1.1
Zabbix Zabbix 1.6.7
Zabbix Zabbix 1.6.6
Zabbix Zabbix 1.3.2
Zabbix Zabbix 1.3.3
Zabbix Zabbix 1.7
Zabbix Zabbix 1.4.3
Zabbix Zabbix 1.1.5
Zabbix Zabbix 1.5.1
Zabbix Zabbix 1.5
Zabbix Zabbix 1.6.4
Zabbix Zabbix 1.6.3
Zabbix Zabbix 1.7.1
Zabbix Zabbix 1.7.3
Zabbix Zabbix 1.1.1
Zabbix Zabbix 1.3.4
Zabbix Zabbix 1.3.5
Zabbix Zabbix 1.4.4
Zabbix Zabbix 1.4.5
Zabbix Zabbix 1.3.8
Zabbix Zabbix 1.6.2
668
VMScore
CVE-2010-1277
SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 prior to 1.8.2 allows remote malicious users to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.
Zabbix Zabbix 1.8
Zabbix Zabbix 1.8.1
490
VMScore
CVE-2014-1685
The Frontend in Zabbix prior to 1.8.20rc2, 2.0.x prior to 2.0.11rc2, and 2.2.x prior to 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.
Zabbix Zabbix 2.0.2
Zabbix Zabbix 2.0.3
Zabbix Zabbix 2.2.1
Zabbix Zabbix 2.2.0
Zabbix Zabbix 2.0.4
Zabbix Zabbix 2.0.5
Zabbix Zabbix 2.0.6
Zabbix Zabbix 1.8
Zabbix Zabbix 2.0.7
Zabbix Zabbix 2.0.8
Zabbix Zabbix 2.0.0
Zabbix Zabbix 2.0.1
Zabbix Zabbix
Zabbix Zabbix 1.8.2
Zabbix Zabbix 1.8.3
Zabbix Zabbix 2.0.9
Zabbix Zabbix 2.0.10
Zabbix Zabbix 1.8.1
Zabbix Zabbix 1.8.16
Fedoraproject Fedora 19
Zabbix Zabbix 1.8.15
Zabbix Zabbix 1.8.18
445
VMScore
CVE-2011-3264
Zabbix prior to 1.8.6 allows remote malicious users to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message.
Zabbix Zabbix 1.7.3
Zabbix Zabbix 1.1
Zabbix Zabbix 1.7.4
Zabbix Zabbix 1.6.6
Zabbix Zabbix 1.1.1
Zabbix Zabbix 1.7.1
Zabbix Zabbix 1.6.8
Zabbix Zabbix 1.3
Zabbix Zabbix 1.3.1
Zabbix Zabbix 1.4.6
Zabbix Zabbix 1.8
Zabbix Zabbix 1.8.1
Zabbix Zabbix 1.8.3
Zabbix Zabbix 1.3.8
Zabbix Zabbix 1.5
Zabbix Zabbix 1.6.2
Zabbix Zabbix 1.8.4
Zabbix Zabbix 1.7.2
Zabbix Zabbix 1.6.7
Zabbix Zabbix 1.3.2
Zabbix Zabbix 1.3.3
Zabbix Zabbix 1.7
445
VMScore
CVE-2011-3265
popup.php in Zabbix prior to 1.8.7 allows remote malicious users to read the contents of arbitrary database tables via a modified srctbl parameter.
Zabbix Zabbix 1.7.3
Zabbix Zabbix 1.1
Zabbix Zabbix 1.6.6
Zabbix Zabbix 1.1.1
Zabbix Zabbix 1.3.4
Zabbix Zabbix 1.3.5
Zabbix Zabbix 1.4.4
Zabbix Zabbix 1.4.3
Zabbix Zabbix 1.1.5
Zabbix Zabbix 1.3.6
Zabbix Zabbix 1.5.3
Zabbix Zabbix 1.5.4
Zabbix Zabbix 1.6.9
Zabbix Zabbix 1.6.5
Zabbix Zabbix 1.7.2
Zabbix Zabbix 1.6.7
Zabbix Zabbix 1.3.2
Zabbix Zabbix 1.3.3
Zabbix Zabbix 1.7
Zabbix Zabbix 1.1.4
Zabbix Zabbix 1.4.2
Zabbix Zabbix 1.3.7
445
VMScore
CVE-2011-3263
zabbix_agentd in Zabbix prior to 1.8.6 and 1.9.x prior to 1.9.4 allows context-dependent malicious users to cause a denial of service (CPU consumption) by executing the vfs.file.cksum command for a special device, as demonstrated by the /dev/urandom device.
Zabbix Zabbix 1.7.1
Zabbix Zabbix 1.1
Zabbix Zabbix 1.6.8
Zabbix Zabbix 1.1.7
Zabbix Zabbix 1.3
Zabbix Zabbix 1.4.6
Zabbix Zabbix 1.1.2
Zabbix Zabbix 1.8
Zabbix Zabbix 1.4.5
Zabbix Zabbix 1.8.3
Zabbix Zabbix 1.5.1
Zabbix Zabbix 1.5
Zabbix Zabbix 1.6.3
Zabbix Zabbix
Zabbix Zabbix 1.7.2
Zabbix Zabbix 1.7.4
Zabbix Zabbix 1.1.1
Zabbix Zabbix 1.1.6
Zabbix Zabbix 1.3.5
Zabbix Zabbix 1.4.4
Zabbix Zabbix 1.8.2
Zabbix Zabbix 1.1.3
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »