VYPR

Zabbix

by Zabbix

Source repositories

CVEs (121)

  • CVE-2021-27927HigMar 3, 2021
    risk 0.57cvss 8.8epss 0.01

    In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the…

  • CVE-2016-4338HigJan 23, 2017
    risk 0.57cvss 8.1epss 0.21

    The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via…

  • CVE-2023-32723HigOct 12, 2023
    risk 0.55cvss 8.5epss 0.01

    Request to LDAP is sent before user permissions are checked.

  • CVE-2023-29450HigJul 13, 2023
    risk 0.55cvss 8.5epss 0.01

    JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

  • CVE-2017-2824HigMay 24, 2017
    risk 0.55cvss 8.1epss 0.26

    An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to…

  • CVE-2026-23925HigMar 6, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit…

  • CVE-2024-36460HigAug 12, 2024
    risk 0.53cvss 8.1epss 0.01

    The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

  • CVE-2026-23920HigMar 24, 2026
    risk 0.50cvss epss 0.00

    Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.

  • CVE-2024-36467HigNov 27, 2024
    risk 0.49cvss 7.5epss 0.01

    An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having…

  • CVE-2024-36462HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance…

  • CVE-2023-32721HigOct 12, 2023
    risk 0.49cvss 7.6epss 0.01

    A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.

  • CVE-2013-7484HigNov 30, 2019
    risk 0.49cvss 7.5epss 0.01

    Zabbix before 5.0 represents passwords in the users table with unsalted MD5.

  • CVE-2026-23926HigMay 6, 2026
    risk 0.47cvss epss 0.00

    An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on…

  • CVE-2025-27240HigSep 12, 2025
    risk 0.47cvss 7.2epss 0.01

    A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.

  • CVE-2025-27234HigSep 12, 2025
    risk 0.47cvss epss 0.00

    Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.

  • CVE-2021-46088HigJan 27, 2022
    risk 0.47cvss 7.2epss 0.04

    Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.

  • CVE-2026-23919HigMar 24, 2026
    risk 0.46cvss epss 0.00

    For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A…

  • CVE-2017-2825HigApr 20, 2018
    risk 0.46cvss 7.0epss 0.04

    In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to…

  • CVE-2026-23923MedMar 24, 2026
    risk 0.45cvss epss 0.00

    An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

  • CVE-2023-32727MedDec 18, 2023
    risk 0.44cvss 6.8epss 0.01

    An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.

Page 2 of 7