İçeriğe atla
Noroxi

Zabbix kayıtları

zabbix üreticisine ait 135 yayımlanmış kayıt.

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

135 kayıt
  • Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %96

    zabbix · zabbix13 Oca 2022

  • Possible view of the setup pages by unauthenticated users if config file already exists

    OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %95

    zabbix · zabbix13 Oca 2022

  • CVE-2016-10134
    64Bu hafta

    SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the t

    KritikCVSS 9,8SilahlaştırılmışEPSS %83

    zabbix · zabbix16 Şub 2017

  • CVE-2013-5743
    63Bu hafta

    Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

    KritikCVSS 9,8SilahlaştırılmışEPSS %80

    zabbix · zabbix11 Ara 2019

  • CVE-2024-42327
    63Bu hafta

    SQL injection in user.get API

    KritikCVSS 9,9Kavram kanıtıEPSS %79

    zabbix · zabbix27 Kas 2024

  • CVE-2024-22120
    58Planlayın

    Time Based SQL Injection in Zabbix Server Audit Log

    YüksekCVSS 8,8Kavram kanıtıEPSS %77

    zabbix · zabbix17 May 2024

  • CVE-2013-3628
    55Planlayın

    Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

    YüksekCVSS 8,8SilahlaştırılmışEPSS %67

    zabbix · zabbix7 Şub 2020

  • CVE-2019-17382
    52Planlayın

    An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4.

    KritikCVSS 9,1Kavram kanıtıEPSS %54

    zabbix · zabbix9 Eki 2019

  • CVE-2024-36465
    46Planlayın

    SQL injection in Zabbix API

    YüksekCVSS 8,6İstismar yokEPSS %40

    zabbix · zabbix2 Nis 2025

  • CVE-2009-4502
    43Planlayın

    The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the

    KritikCVSS 9,3SilahlaştırılmışEPSS %22

    zabbix · zabbix31 Ara 2009

  • CVE-2020-11800
    42Planlayın

    Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    zabbix · zabbix7 Eki 2020

  • CVE-2014-3005
    41Planlayın

    XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.

    KritikCVSS 9,8İstismar yokEPSS %5

    zabbix · zabbix1 Şub 2018

  • CVE-2007-0640
    41Planlayın

    Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."

    KritikCVSS 10,0İstismar yokEPSS %2

    zabbix · zabbix31 Oca 2007

  • CVE-2023-29452
    40Planlayın

    Remove possibility to add html into Geomap attribution field

    OrtaCVSS 5,4İstismar yokEPSS %64

    zabbix · zabbix13 Tem 2023

  • CVE-2017-2824
    40Planlayın

    An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X.

    YüksekCVSS 8,1Kavram kanıtıEPSS %26

    zabbix · zabbix24 May 2017

  • CVE-2013-3738
    40Planlayın

    A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a re

    KritikCVSS 9,8İstismar yokEPSS %3

    zabbix · zabbix17 Şub 2020

  • CVE-2022-22704
    39İzleyin

    The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expe

    KritikCVSS 9,8İstismar yokEPSS %1

    zabbix · zabbix-agent26 Oca 2022

  • CVE-2022-43515
    39İzleyin

    X-Forwarded-For header is active by default causes access to Zabbix sites in maintenance mode

    KritikCVSS 9,8İstismar yokEPSS %1

    zabbix · frontend5 Ara 2022

  • CVE-2022-43516
    39İzleyin

    Zabbix Agent installer adds “allow all TCP any any” firewall rule

    KritikCVSS 9,8İstismar yokEPSS %1

    microsoft · windows firewall5 Ara 2022

  • CVE-2023-32728
    39İzleyin

    Code injection in zabbix_agent2 smart.disk.get caused by smartctl plugin

    KritikCVSS 9,8İstismar yokEPSS %1

    zabbix · zabbix-agent218 Ara 2023

  • CVE-2023-29453
    39İzleyin

    Agent 2 package are built with Go version affected by CVE-2023-24538

    KritikCVSS 9,8İstismar yokEPSS %1

    zabbix · zabbix-agent212 Eki 2023

  • CVE-2016-4338
    38İzleyin

    The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.

    YüksekCVSS 8,1Kavram kanıtıEPSS %21

    zabbix · zabbix23 Oca 2017

  • CVE-2022-46768
    37İzleyin

    File name information disclosure vulnerability in Zabbix Web Service Report Generation

    OrtaCVSS 5,9İstismar yokEPSS %48

    zabbix · web service report generation15 Ara 2022

  • CVE-2009-4498
    37İzleyin

    The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.

    OrtaCVSS 6,8SilahlaştırılmışEPSS %32

    zabbix · zabbix31 Ara 2009

  • CVE-2021-27927
    36İzleyin

    In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControll

    YüksekCVSS 8,8İstismar yokEPSS %2

    zabbix · zabbix3 Mar 2021