Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zabbix zabbix vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2013-6824
Zabbix prior to 1.8.19rc1, 2.0 prior to 2.0.10rc1, and 2.2 prior to 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter.
Zabbix Zabbix
Zabbix Zabbix 2.0.0
Zabbix Zabbix 2.2.0
445
VMScore
CVE-2013-1364
The user.login function in Zabbix prior to 1.8.16 and 2.x prior to 2.0.5rc1 allows remote malicious users to override LDAP configuration via the cnf parameter.
Zabbix Zabbix 2.0.0
Zabbix Zabbix 2.0.4
Zabbix Zabbix 2.0.3
Zabbix Zabbix 2.0.2
Zabbix Zabbix 2.0.1
Zabbix Zabbix
355
VMScore
CVE-2013-5572
Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.
Zabbix Zabbix 2.0.5
1 EDB exploit
755
VMScore
CVE-2012-3435
SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and previous versions, and 2.x prior to 2.0.2rc1, allows remote malicious users to execute arbitrary SQL commands via the itemid parameter.
Zabbix Zabbix
Zabbix Zabbix 1.7.4
Zabbix Zabbix 1.1
Zabbix Zabbix 1.1.6
Zabbix Zabbix 1.1.7
Zabbix Zabbix 1.4.6
Zabbix Zabbix 1.8.2
Zabbix Zabbix 1.1.3
Zabbix Zabbix 1.8.3
Zabbix Zabbix 1.4.5
Zabbix Zabbix 1.5.2
Zabbix Zabbix 1.5.1
Zabbix Zabbix 1.7.1
Zabbix Zabbix 1.6.8
Zabbix Zabbix 1.3
Zabbix Zabbix 1.3.1
Zabbix Zabbix 1.1.2
Zabbix Zabbix 1.8
Zabbix Zabbix 1.8.1
Zabbix Zabbix 1.3.8
Zabbix Zabbix 1.5
Zabbix Zabbix 1.6.2
1 EDB exploit
383
VMScore
CVE-2011-4615
Multiple cross-site scripting (XSS) vulnerabilities in Zabbix prior to 1.8.10 allow remote malicious users to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) ...
Zabbix Zabbix
Zabbix Zabbix 1.8.10
Zabbix Zabbix 1.8.7
Zabbix Zabbix 1.8.4
Zabbix Zabbix 1.8.3
Zabbix Zabbix 1.8.2
Zabbix Zabbix 1.6.9
Zabbix Zabbix 1.6.8
Zabbix Zabbix 1.6.1
Zabbix Zabbix 1.6
Zabbix Zabbix 1.4.5
Zabbix Zabbix 1.4.4
Zabbix Zabbix 1.3.5
Zabbix Zabbix 1.3.4
Zabbix Zabbix 1.1.5
Zabbix Zabbix 1.1.4
Zabbix Zabbix 1.1
Zabbix Zabbix 1.8.9
Zabbix Zabbix 1.8.8
Zabbix Zabbix 1.8.6
Zabbix Zabbix 1.8.5
Zabbix Zabbix 1.7.4
383
VMScore
CVE-2011-5027
Cross-site scripting (XSS) vulnerability in ZABBIX prior to 1.8.10 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors related to the profiler.
Zabbix Zabbix
Zabbix Zabbix 1.8.8
Zabbix Zabbix 1.8.5
Zabbix Zabbix 1.8.4
Zabbix Zabbix 1.8.3
Zabbix Zabbix 1.7.1
Zabbix Zabbix 1.7
Zabbix Zabbix 1.6.3
Zabbix Zabbix 1.6.2
Zabbix Zabbix 1.6.1
Zabbix Zabbix 1.4.6
Zabbix Zabbix 1.4.5
Zabbix Zabbix 1.3.7
Zabbix Zabbix 1.3.6
Zabbix Zabbix 1.1.6
Zabbix Zabbix 1.1.5
Zabbix Zabbix 1.1
Zabbix Zabbix 1.8.9
Zabbix Zabbix 1.8.6
Zabbix Zabbix 1.8
Zabbix Zabbix 1.7.4
Zabbix Zabbix 1.6.7
755
VMScore
CVE-2011-4674
SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions prior to 1.8.9, allows remote malicious users to execute arbitrary SQL commands via the only_hostid parameter.
Zabbix Zabbix 1.8.4
Zabbix Zabbix 1.8.3
1 EDB exploit
668
VMScore
CVE-2010-5049
SQL injection vulnerability in events.php in Zabbix 1.8.1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the nav_time parameter.
Zabbix Zabbix 1.7.2
Zabbix Zabbix 1.1
Zabbix Zabbix 1.6.7
Zabbix Zabbix 1.6.6
Zabbix Zabbix 1.3.2
Zabbix Zabbix 1.3.3
Zabbix Zabbix 1.7
Zabbix Zabbix 1.4.3
Zabbix Zabbix 1.1.5
Zabbix Zabbix 1.5.1
Zabbix Zabbix 1.5
Zabbix Zabbix 1.6.4
Zabbix Zabbix 1.6.3
Zabbix Zabbix 1.7.1
Zabbix Zabbix 1.7.3
Zabbix Zabbix 1.1.1
Zabbix Zabbix 1.3.4
Zabbix Zabbix 1.3.5
Zabbix Zabbix 1.4.4
Zabbix Zabbix 1.4.5
Zabbix Zabbix 1.3.8
Zabbix Zabbix 1.6.2
383
VMScore
CVE-2011-2904
Cross-site scripting (XSS) vulnerability in acknow.php in Zabbix prior to 1.8.6 allows remote malicious users to inject arbitrary web script or HTML via the backurl parameter.
Zabbix Zabbix 1.7.1
Zabbix Zabbix 1.1
Zabbix Zabbix 1.7.4
Zabbix Zabbix 1.1.1
Zabbix Zabbix 1.1.6
Zabbix Zabbix 1.3.5
Zabbix Zabbix 1.8.2
Zabbix Zabbix 1.1.3
Zabbix Zabbix 1.1.5
Zabbix Zabbix 1.8.3
Zabbix Zabbix 1.5.3
Zabbix Zabbix 1.5.2
Zabbix Zabbix 1.6.5
Zabbix Zabbix 1.6.4
Zabbix Zabbix 1.8.5
Zabbix Zabbix 1.8.4
Zabbix Zabbix 1.7.3
Zabbix Zabbix 1.6.6
Zabbix Zabbix 1.3.3
Zabbix Zabbix 1.3.4
Zabbix Zabbix 1.7
Zabbix Zabbix 1.4.4
445
VMScore
CVE-2011-3263
zabbix_agentd in Zabbix prior to 1.8.6 and 1.9.x prior to 1.9.4 allows context-dependent malicious users to cause a denial of service (CPU consumption) by executing the vfs.file.cksum command for a special device, as demonstrated by the /dev/urandom device.
Zabbix Zabbix 1.7.1
Zabbix Zabbix 1.1
Zabbix Zabbix 1.6.8
Zabbix Zabbix 1.1.7
Zabbix Zabbix 1.3
Zabbix Zabbix 1.4.6
Zabbix Zabbix 1.1.2
Zabbix Zabbix 1.8
Zabbix Zabbix 1.4.5
Zabbix Zabbix 1.8.3
Zabbix Zabbix 1.5.1
Zabbix Zabbix 1.5
Zabbix Zabbix 1.6.3
Zabbix Zabbix
Zabbix Zabbix 1.7.2
Zabbix Zabbix 1.7.4
Zabbix Zabbix 1.1.1
Zabbix Zabbix 1.1.6
Zabbix Zabbix 1.3.5
Zabbix Zabbix 1.4.4
Zabbix Zabbix 1.8.2
Zabbix Zabbix 1.1.3
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege escalation
CVE-2024-20696
CVE-2024-29829
CVE-2024-33999
CVE-2024-35646
physical
CVE-2024-24919
CVE-2024-31030
local users
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
NEXT »