Show filters
102 Total Results
Displaying 21-30 of 102
Sort by:
Attacker Value
Unknown

CVE-2024-22116

Disclosure Date: August 12, 2024 (last updated December 21, 2024)
An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.
Attacker Value
Unknown

CVE-2024-22114

Disclosure Date: August 12, 2024 (last updated December 21, 2024)
User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard.
Attacker Value
Unknown

CVE-2024-22120

Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
0
Attacker Value
Unknown

CVE-2024-22119

Disclosure Date: February 09, 2024 (last updated February 16, 2024)
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.
Attacker Value
Unknown

CVE-2023-32728

Disclosure Date: December 18, 2023 (last updated December 23, 2023)
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.
Attacker Value
Unknown

CVE-2023-32727

Disclosure Date: December 18, 2023 (last updated December 23, 2023)
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
Attacker Value
Unknown

CVE-2023-32726

Disclosure Date: December 18, 2023 (last updated December 23, 2023)
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
Attacker Value
Unknown

CVE-2023-32725

Disclosure Date: December 18, 2023 (last updated December 23, 2023)
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
Attacker Value
Unknown

CVE-2023-32724

Disclosure Date: October 12, 2023 (last updated October 18, 2023)
Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.
Attacker Value
Unknown

CVE-2023-32723

Disclosure Date: October 12, 2023 (last updated October 18, 2023)
Request to LDAP is sent before user permissions are checked.