Loading HuntDB...

zabbix

138 Versions 43 CVEs

Versions

7.0.1rc

RC 1 CVE

2.0.9

SEMANTIC 1 CVE

4.0.45

SEMANTIC 3 CVEs

6.4.0rc1

RC 1 CVE

6.4.16rc1

RC 8 CVEs

5.0.0

SEMANTIC 16 CVEs

4.4.7rc1

RC 1 CVE

4.0.47rc1

RC 1 CVE

4.0.49

SEMANTIC 1 CVE

7.0.0alpha1

ALPHA 22 CVEs

4.4.*

OTHER 1 CVE

7.0.5rc1

RC 1 CVE

6.0.30

SEMANTIC 6 CVEs

5.0.0alpha4

ALPHA 1 CVE

6.4.7

SEMANTIC 1 CVE

6.0.20

SEMANTIC 3 CVEs

6.0.22rc1

RC 1 CVE

4.0.48rc1

RC 1 CVE

6.4.3rc1

RC 1 CVE

6.0.34rc1

RC 3 CVEs

6.4.0beta6

BETA 1 CVE

7.0.0alpha6

ALPHA 1 CVE

6.0.22

SEMANTIC 1 CVE

6.4.4rc1

RC 1 CVE

7.0.0alpha3

ALPHA 4 CVEs

5.0.0alpha1

ALPHA 2 CVEs

5.0.42

SEMANTIC 7 CVEs

6.2.9rc2

RC 1 CVE

6.0.16

SEMANTIC 1 CVE

4.0.0

SEMANTIC 7 CVEs

6.4.13rc1

RC 1 CVE

5.0.44rc1

RC 1 CVE

6.4.12

SEMANTIC 1 CVE

6.4.6

SEMANTIC 1 CVE

6.2.8rc1

RC 2 CVEs

6.0.19rc1

RC 1 CVE

4.4.8rc1

RC 1 CVE

6.4.8

SEMANTIC 3 CVEs

5.0.39rc1

RC 1 CVE

4.4.0

SEMANTIC 1 CVE

5.4.0alpha1

ALPHA 1 CVE

6.4.7rc1

RC 1 CVE

6,0,0

OTHER 1 CVE

6.4.2rc1

RC 1 CVE

7.0.0alpha2

ALPHA 1 CVE

7.0.1rc1

RC 3 CVEs

5.0.35

SEMANTIC 2 CVEs

6.0.24

SEMANTIC 1 CVE

7.0.2

SEMANTIC 2 CVEs

5.0.32rc1

RC 2 CVEs

7.0.0beta1

BETA 1 CVE

4.0.47

SEMANTIC 1 CVE

6.0.29

SEMANTIC 1 CVE

6.4.19rc1

RC 3 CVEs

5.0.40

SEMANTIC 1 CVE

6.0.33rc1

RC 2 CVEs

6.0.35rc1

RC 1 CVE

7.0.3

SEMANTIC 5 CVEs

7.0.0alpha7

ALPHA 4 CVEs

5.0.34

SEMANTIC 3 CVEs

6.0.23

SEMANTIC 3 CVEs

6.4.0

SEMANTIC 29 CVEs

7.0.2rc1

RC 3 CVEs

6.4.3

SEMANTIC 2 CVEs

5.0.43rc1

RC 7 CVEs

6.2.8

SEMANTIC 1 CVE

6.2

MAJOR_MINOR 2 CVEs

5.0.38

SEMANTIC 2 CVEs

5.2.*

OTHER 1 CVE

6.4.20rc1

RC 1 CVE

7.0.0alpha8

ALPHA 3 CVEs

6.0.21rc1

RC 3 CVEs

5.0.43

SEMANTIC 1 CVE

6.0.32rc1

RC 2 CVEs

6.0.32

SEMANTIC 2 CVEs

4.0.19rc1

RC 1 CVE

6.0.13

SEMANTIC 2 CVEs

6.0.28rc1

RC 1 CVE

4.0.46

SEMANTIC 1 CVE

5.0

MAJOR_MINOR 1 CVE

6.0.31

SEMANTIC 2 CVEs

7.0.4rc1

RC 6 CVEs

7.0.0

SEMANTIC 17 CVEs

7.0.1

SEMANTIC 1 CVE

5.0.40rc1

RC 1 CVE

6.4.1rc2

RC 1 CVE

6.0.15rc1

RC 1 CVE

6.0.30rc1

RC 1 CVE

5,0,0

OTHER 5 CVEs

6.4.18

SEMANTIC 3 CVEs

7.0.0alpha4

ALPHA 4 CVEs

6.0.27

SEMANTIC 1 CVE

7.0.3rc1

RC 4 CVEs

4.0.46rc1

RC 3 CVEs

6.0.21

SEMANTIC 1 CVE

6.4.2

SEMANTIC 3 CVEs

6.0.18rc1

RC 4 CVEs

6.0.23rc1

RC 1 CVE

4.4.4

SEMANTIC 1 CVE

6.0.33

SEMANTIC 3 CVEs

6.4.6rc1

RC 3 CVEs

5.2.0alpha1

ALPHA 1 CVE

7.2.0alpha1

ALPHA 1 CVE

6.0

MAJOR_MINOR 3 CVEs

6.4.9

SEMANTIC 2 CVEs

6.4

MAJOR_MINOR 2 CVEs

6.4.8rc1

RC 1 CVE

5.0.31

SEMANTIC 2 CVEs

6.4.15

SEMANTIC 8 CVEs

6.0.0alpha1

ALPHA 1 CVE

6.0.31rc1

RC 6 CVEs

6.4.0alpha1

ALPHA 1 CVE

5.0.36rc1

RC 1 CVE

5.4.*

OTHER 1 CVE

7.0.0rc2

RC 7 CVEs

5.0.35rc1

RC 4 CVEs

7.0.0rc3

RC 6 CVEs

5.0.37rc1

RC 2 CVEs

4.0.50

SEMANTIC 1 CVE

6.0.14

SEMANTIC 1 CVE

6.0.14rc1 (6.0.16 is recommended)

RC 2 CVEs

6.0.18

SEMANTIC 2 CVEs

6.4.18rc1

RC 2 CVEs

6.4.16

SEMANTIC 2 CVEs

5.0.39

SEMANTIC 3 CVEs

6.4.17

SEMANTIC 2 CVEs

4.0.20rc1

RC 1 CVE

5.0.33

SEMANTIC 2 CVEs

6.4.0rc2

RC 2 CVEs

6.0.24rc1

RC 2 CVEs

6.0.17

SEMANTIC 4 CVEs

5.0.36

SEMANTIC 2 CVEs

6.2.0alpha1

ALPHA 1 CVE

6.0.0

SEMANTIC 28 CVEs

6.4.9rc1

RC 2 CVEs

6.2.7

SEMANTIC 2 CVEs

6.4.5

SEMANTIC 3 CVEs

6.4.17rc1

RC 2 CVEs

Recent CVEs

CVE-2024-22114

User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard.

MEDIUM Aug 09, 2024

CVE-2024-36461

Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

CRITICAL Aug 09, 2024

CVE-2024-22120

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

CRITICAL May 17, 2024

CVE-2023-32728

The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.

MEDIUM Dec 18, 2023

CVE-2023-32726

The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.

LOW Dec 18, 2023

CVE-2023-32725

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

CRITICAL Dec 18, 2023

CVE-2023-29456

URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.

MEDIUM Jul 13, 2023

CVE-2023-29454

Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.

MEDIUM Jul 13, 2023

CVE-2023-29452

Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.

MEDIUM Jul 13, 2023

CVE-2023-29451

Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.

MEDIUM Jul 13, 2023