VYPR

Zabbix

by Zabbix

Source repositories

CVEs (118)

  • CVE-2016-10134CriFeb 17, 2017
    risk 0.73cvss 9.8epss 0.83

    SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

  • CVE-2014-3005CriFeb 1, 2018
    risk 0.64cvss 9.8epss 0.05

    XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.

  • CVE-2016-4338HigJan 23, 2017
    risk 0.57cvss 8.1epss 0.21

    The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via…

  • CVE-2017-2824HigMay 24, 2017
    risk 0.55cvss 8.1epss 0.26

    An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to…

  • CVE-2026-23925HigMar 6, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit…

  • CVE-2026-23928HigMay 6, 2026
    risk 0.47cvss epss 0.00

    The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The…

  • CVE-2026-23926HigMay 6, 2026
    risk 0.47cvss epss 0.00

    An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on…

  • CVE-2025-27234HigSep 12, 2025
    risk 0.47cvss epss 0.00

    Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.

  • CVE-2022-23131KEVJan 13, 2022
    risk 0.20cvss epss 0.96

    In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and…

  • CVE-2022-23134KEVJan 13, 2022
    risk 0.19cvss epss 0.85

    After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

  • CVE-2013-3628Feb 7, 2020
    risk 0.10cvss epss 0.67

    Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

  • CVE-2013-5743Dec 11, 2019
    risk 0.09cvss epss 0.80

    Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

  • CVE-2024-22120May 17, 2024
    risk 0.07cvss epss 0.77

    Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

  • CVE-2019-17382Oct 9, 2019
    risk 0.07cvss epss 0.54

    An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All…

  • CVE-2009-4498Dec 31, 2009
    risk 0.06cvss epss 0.32

    The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.

  • CVE-2009-4502Dec 31, 2009
    risk 0.05cvss epss 0.22

    The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands via shell metacharacters in the argument to net.tcp.listen. NOTE: this attack…

  • CVE-2020-11800Oct 7, 2020
    risk 0.04cvss epss 0.09

    Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.

  • CVE-2009-4501Dec 31, 2009
    risk 0.04cvss epss 0.09

    The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service (crash) via a request that lacks expected separators, which triggers a NULL pointer dereference, as demonstrated using the Command keyword.

  • CVE-2006-6692Dec 21, 2006
    risk 0.04cvss epss 0.08

    Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in information that would be recorded in the system log using (1) zabbix_log or (2)…

  • CVE-2024-42327Nov 27, 2024
    risk 0.03cvss epss 0.79

    A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function…

Page 1 of 6