Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zabbix zabbix vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2017-2826
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker ca...
Zabbix Zabbix 2.4.1
Zabbix Zabbix 2.4.2
Zabbix Zabbix 2.4.6
Zabbix Zabbix 2.4.7
Zabbix Zabbix 2.4.9
Zabbix Zabbix 2.4.3
Zabbix Zabbix 2.4.4
Zabbix Zabbix 2.4.5
Zabbix Zabbix 2.4.0
Zabbix Zabbix 2.4.8
Debian Debian Linux 8.0
7.5
CVSSv2
CVE-2014-3005
XML external entity (XXE) vulnerability in Zabbix 1.8.x prior to 1.8.21rc1, 2.0.x prior to 2.0.13rc1, 2.2.x prior to 2.2.5rc1, and 2.3.x prior to 2.3.2 allows remote malicious users to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
Zabbix Zabbix 2.2.1
Zabbix Zabbix 2.2.3
Zabbix Zabbix 2.0.5
Zabbix Zabbix 2.0.7
Zabbix Zabbix 2.0.12
Zabbix Zabbix 1.8.1
Zabbix Zabbix 1.8.8
Zabbix Zabbix 1.8.10
Zabbix Zabbix 1.8.17
Zabbix Zabbix 1.8.19
Zabbix Zabbix 2.3.0
Zabbix Zabbix 2.3.1
Zabbix Zabbix 2.2.0
Zabbix Zabbix 2.0.8
Zabbix Zabbix 2.0.9
Zabbix Zabbix 2.0.10
Zabbix Zabbix 2.0.11
Zabbix Zabbix 1.8.12
Zabbix Zabbix 1.8.13
Zabbix Zabbix 1.8.14
Zabbix Zabbix 1.8.15
Zabbix Zabbix 2.0.0
6.8
CVSSv2
CVE-2017-2824
An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to trigge...
Zabbix Zabbix 2.4.1
Zabbix Zabbix 2.4.9
Zabbix Zabbix 2.4.2
Zabbix Zabbix 2.4.0
Zabbix Zabbix 2.4.4
Zabbix Zabbix 2.4.3
Zabbix Zabbix 2.4.6
Zabbix Zabbix 2.4.5
Zabbix Zabbix 2.4.8
Zabbix Zabbix 2.4.7
2 Github repositories
7.5
CVSSv2
CVE-2016-10134
SQL injection vulnerability in Zabbix prior to 2.2.14 and 3.0 prior to 3.0.4 allows remote malicious users to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
Zabbix Zabbix 3.0.0
Zabbix Zabbix 3.0.2
Zabbix Zabbix
Zabbix Zabbix 3.0.3
Zabbix Zabbix 3.0.1
6.8
CVSSv2
CVE-2016-4338
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix prior to 2.0.18, 2.2.x prior to 2.2.13, and 3.0.x prior to 3.0.3, when used with a shell other than bash, allows context-dependent malicious users to execute arbitrary code or SQL comm...
Zabbix Zabbix 2.0.14
Zabbix Zabbix 2.0.13
Zabbix Zabbix 2.0.6
Zabbix Zabbix 2.0.5
Zabbix Zabbix 2.2.10
Zabbix Zabbix 2.2.9
Zabbix Zabbix 2.0.12
Zabbix Zabbix 2.0.11
Zabbix Zabbix 2.0.4
Zabbix Zabbix 2.0.3
Zabbix Zabbix 2.0.2
Zabbix Zabbix 2.2.8
Zabbix Zabbix 2.2.7
Zabbix Zabbix 2.2.0
Zabbix Zabbix 3.0.2
Zabbix Zabbix 2.2.2
Zabbix Zabbix 2.2.1
Zabbix Zabbix 2.0.17
Zabbix Zabbix 2.0.10
Zabbix Zabbix 2.0.9
Zabbix Zabbix 2.0.1
Zabbix Zabbix 2.0.0
1 EDB exploit
7.5
CVSSv2
CVE-2014-9450
Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix prior to 1.8.22, 2.0.x prior to 2.0.14, and 2.2.x prior to 2.2.8 allow remote malicious users to execute arbitrary SQL commands via the (1) itemid or (2) periods parameter.
Zabbix Zabbix 2.0.4
Zabbix Zabbix 2.0.5
Zabbix Zabbix 2.0.2
Zabbix Zabbix 2.0.3
Zabbix Zabbix 2.0.6
Zabbix Zabbix 2.0.8
Zabbix Zabbix 2.0.11
Zabbix Zabbix 2.0.10
Zabbix Zabbix 2.0.9
Zabbix Zabbix 2.0.13
Zabbix Zabbix 2.2.0
Zabbix Zabbix 2.2.2
Zabbix Zabbix 2.2.3
Zabbix Zabbix 2.2.4
Zabbix Zabbix 2.0.1
Zabbix Zabbix 2.2.1
Zabbix Zabbix 2.2.6
Zabbix Zabbix 2.2.7
Zabbix Zabbix
Zabbix Zabbix 2.0.7
Zabbix Zabbix 2.2.5
Zabbix Zabbix 2.0.12
4
CVSSv2
CVE-2014-1682
The API in Zabbix prior to 1.8.20rc1, 2.0.x prior to 2.0.11rc1, and 2.2.x prior to 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
Zabbix Zabbix 2.0.2
Zabbix Zabbix 2.0.3
Zabbix Zabbix 2.0.7
Zabbix Zabbix 2.0.8
Zabbix Zabbix 2.2.0
Zabbix Zabbix 2.2.1
Zabbix Zabbix 2.0.0
Zabbix Zabbix 2.0.1
Zabbix Zabbix 2.0.5
Zabbix Zabbix 1.8
Zabbix Zabbix 1.8.3
Zabbix Zabbix 2.0.9
Zabbix Zabbix 2.0.10
Zabbix Zabbix 2.0.4
Fedoraproject Fedora 19
Fedoraproject Fedora 20
Zabbix Zabbix 2.0.6
Zabbix Zabbix 1.8.15
Zabbix Zabbix 1.8.16
Zabbix Zabbix 1.8.18
Zabbix Zabbix
Zabbix Zabbix 1.8.1
5.5
CVSSv2
CVE-2014-1685
The Frontend in Zabbix prior to 1.8.20rc2, 2.0.x prior to 2.0.11rc2, and 2.2.x prior to 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.
Zabbix Zabbix 2.0.2
Zabbix Zabbix 2.0.3
Zabbix Zabbix 2.2.1
Zabbix Zabbix 2.2.0
Zabbix Zabbix 2.0.4
Zabbix Zabbix 2.0.5
Zabbix Zabbix 2.0.6
Zabbix Zabbix 1.8
Zabbix Zabbix 2.0.7
Zabbix Zabbix 2.0.8
Zabbix Zabbix 2.0.0
Zabbix Zabbix 2.0.1
Zabbix Zabbix
Zabbix Zabbix 1.8.2
Zabbix Zabbix 1.8.3
Zabbix Zabbix 2.0.9
Zabbix Zabbix 2.0.10
Zabbix Zabbix 1.8.1
Zabbix Zabbix 1.8.16
Fedoraproject Fedora 19
Zabbix Zabbix 1.8.15
Zabbix Zabbix 1.8.18
4.3
CVSSv2
CVE-2012-6086
libs/zbxmedia/eztexting.c in Zabbix 1.8.x prior to 1.8.18rc1, 2.0.x prior to 2.0.8rc1, and 2.1.x prior to 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certific...
Zabbix Zabbix 2.0.0
Zabbix Zabbix 2.0.1
Zabbix Zabbix 2.0.6
Zabbix Zabbix 2.1.0
Zabbix Zabbix 2.1.1
Zabbix Zabbix 2.0.5
Zabbix Zabbix 1.8.1
Zabbix Zabbix 1.8.10
Zabbix Zabbix 2.0.3
Zabbix Zabbix 1.8.16
Zabbix Zabbix 2.0.2
Zabbix Zabbix 2.0.4
Zabbix Zabbix 1.8.15
7.5
CVSSv2
CVE-2013-6824
Zabbix prior to 1.8.19rc1, 2.0 prior to 2.0.10rc1, and 2.2 prior to 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter.
Zabbix Zabbix
Zabbix Zabbix 2.0.0
Zabbix Zabbix 2.2.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
IMAP
CVE-2024-4367
server-side request forgery
information disclosure
CVE-2024-34342
CVE-2024-4281
CVE-2024-3507
CVE-2024-25560
CVE-2024-34574
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »