VYPR

Zabbix

by Zabbix

Source repositories

CVEs (121)

  • CVE-2022-23131CriKEVJan 13, 2022
    risk 0.79cvss 9.1epss 0.96

    In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and…

  • CVE-2013-5743CriDec 11, 2019
    risk 0.73cvss 9.8epss 0.80

    Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

  • CVE-2016-10134CriFeb 17, 2017
    risk 0.73cvss 9.8epss 0.83

    SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

  • CVE-2024-42327CriNov 27, 2024
    risk 0.67cvss 9.9epss 0.79

    A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function…

  • CVE-2013-3628HigFeb 7, 2020
    risk 0.66cvss 8.8epss 0.67

    Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

  • CVE-2024-22120CriMay 17, 2024
    risk 0.65cvss 9.1epss 0.77

    Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

  • CVE-2024-22116CriAug 12, 2024
    risk 0.64cvss 9.9epss 0.02

    An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising…

  • CVE-2023-29453CriOct 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the…

  • CVE-2020-11800CriOct 7, 2020
    risk 0.64cvss 9.8epss 0.09

    Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.

  • CVE-2013-3738CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.

  • CVE-2014-3005CriFeb 1, 2018
    risk 0.64cvss 9.8epss 0.05

    XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.

  • CVE-2019-17382CriOct 9, 2019
    risk 0.63cvss 9.1epss 0.54

    An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All…

  • CVE-2023-32725CriDec 18, 2023
    risk 0.62cvss 9.6epss 0.01

    The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

  • CVE-2023-32722CriOct 12, 2023
    risk 0.62cvss 9.6epss 0.01

    The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.

  • CVE-2024-36465HigApr 2, 2025
    risk 0.59cvss 8.8epss 0.26

    A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.

  • CVE-2024-42330CriNov 27, 2024
    risk 0.59cvss 9.1epss 0.01

    The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create…

  • CVE-2024-36461CriAug 12, 2024
    risk 0.59cvss 9.1epss 0.01

    Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

  • CVE-2023-32724CriOct 12, 2023
    risk 0.59cvss 9.1epss 0.01

    Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.

  • CVE-2026-23921HigMar 24, 2026
    risk 0.57cvss epss 0.00

    A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary…

  • CVE-2024-36466HigNov 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.

Page 1 of 7