VYPR

Zabbix

by Zabbix

Source repositories

CVEs (128)

  • CVE-2024-36466HigNov 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.

  • CVE-2021-27927HigMar 3, 2021
    risk 0.57cvss 8.8epss 0.02

    In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the…

  • CVE-2016-4338HigJan 23, 2017
    risk 0.57cvss 8.1epss 0.17

    The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via…

  • CVE-2023-32723HigOct 12, 2023
    risk 0.55cvss 8.5epss 0.01

    Request to LDAP is sent before user permissions are checked.

  • CVE-2023-29450HigJul 13, 2023
    risk 0.55cvss 8.5epss 0.01

    JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

  • CVE-2017-2824HigMay 24, 2017
    risk 0.55cvss 8.1epss 0.22

    An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to…

  • CVE-2026-23925HigMar 6, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit…

  • CVE-2024-36460HigAug 12, 2024
    risk 0.53cvss 8.1epss 0.01

    The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

  • CVE-2026-23933HigAug 18, 2026
    risk 0.50cvss —epss 0.00

    In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used…

  • CVE-2024-36467HigNov 27, 2024
    risk 0.49cvss 7.5epss 0.01

    An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having…

  • CVE-2024-36462HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance…

  • CVE-2023-32721HigOct 12, 2023
    risk 0.49cvss 7.6epss 0.01

    A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.

  • CVE-2013-7484HigNov 30, 2019
    risk 0.49cvss 7.5epss 0.01

    Zabbix before 5.0 represents passwords in the users table with unsalted MD5.

  • CVE-2025-27240HigSep 12, 2025
    risk 0.47cvss 7.2epss 0.01

    A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.

  • CVE-2025-27234HigSep 12, 2025
    risk 0.47cvss —epss 0.00

    Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.

  • CVE-2021-46088HigJan 27, 2022
    risk 0.47cvss 7.2epss 0.04

    Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.

  • CVE-2017-2825HigApr 20, 2018
    risk 0.46cvss 7.0epss 0.05

    In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to…

  • CVE-2026-23935MedAug 18, 2026
    risk 0.44cvss —epss 0.00

    A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.

  • CVE-2026-23926MedMay 6, 2026
    risk 0.44cvss 6.8epss 0.00

    An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on…

  • CVE-2023-32727MedDec 18, 2023
    risk 0.44cvss 6.8epss 0.01

    An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.

Page 2 of 7