← Back

Zabbix Server

zabbix_server

Vendor: Zabbix • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zabbix
1Zabbix Server
Jun 17, 2026
Dec 18, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
1Zabbix
2Frontend
Zabbix Server
Jun 17, 2026
Dec 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.