Zabbix
by Zabbix
Source repositories
CVEs (128)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-36466 | Hig | 0.57 | 8.8 | 0.01 | Nov 28, 2024 | A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions. | ||
| CVE-2021-27927 | Hig | 0.57 | 8.8 | 0.02 | Mar 3, 2021 | In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the… | ||
| CVE-2016-4338 | Hig | 0.57 | 8.1 | 0.17 | Jan 23, 2017 | The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via… | ||
| CVE-2023-32723 | Hig | 0.55 | 8.5 | 0.01 | Oct 12, 2023 | Request to LDAP is sent before user permissions are checked. | ||
| CVE-2023-29450 | Hig | 0.55 | 8.5 | 0.01 | Jul 13, 2023 | JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data. | ||
| CVE-2017-2824 | Hig | 0.55 | 8.1 | 0.22 | May 24, 2017 | An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to… | ||
| CVE-2026-23925 | Hig | 0.53 | 8.1 | 0.00 | Mar 6, 2026 | An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit… | ||
| CVE-2024-36460 | Hig | 0.53 | 8.1 | 0.01 | Aug 12, 2024 | The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text. | ||
| CVE-2026-23933 | Hig | 0.50 | — | 0.00 | Aug 18, 2026 | In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used… | ||
| CVE-2024-36467 | Hig | 0.49 | 7.5 | 0.01 | Nov 27, 2024 | An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having… | ||
| CVE-2024-36462 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2024 | Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance… | ||
| CVE-2023-32721 | Hig | 0.49 | 7.6 | 0.01 | Oct 12, 2023 | A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL. | ||
| CVE-2013-7484 | Hig | 0.49 | 7.5 | 0.01 | Nov 30, 2019 | Zabbix before 5.0 represents passwords in the users table with unsalted MD5. | ||
| CVE-2025-27240 | Hig | 0.47 | 7.2 | 0.01 | Sep 12, 2025 | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. | ||
| CVE-2025-27234 | Hig | 0.47 | — | 0.00 | Sep 12, 2025 | Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution. | ||
| CVE-2021-46088 | Hig | 0.47 | 7.2 | 0.04 | Jan 27, 2022 | Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user. | ||
| CVE-2017-2825 | Hig | 0.46 | 7.0 | 0.05 | Apr 20, 2018 | In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to… | ||
| CVE-2026-23935 | Med | 0.44 | — | 0.00 | Aug 18, 2026 | A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss. | ||
| CVE-2026-23926 | Med | 0.44 | 6.8 | 0.00 | May 6, 2026 | An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on… | ||
| CVE-2023-32727 | Med | 0.44 | 6.8 | 0.01 | Dec 18, 2023 | An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server. |
- risk 0.57cvss 8.8epss 0.01
A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
- risk 0.57cvss 8.8epss 0.02
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the…
- risk 0.57cvss 8.1epss 0.17
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via…
- risk 0.55cvss 8.5epss 0.01
Request to LDAP is sent before user permissions are checked.
- risk 0.55cvss 8.5epss 0.01
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
- risk 0.55cvss 8.1epss 0.22
An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to…
- risk 0.53cvss 8.1epss 0.00
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit…
- risk 0.53cvss 8.1epss 0.01
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
- risk 0.50cvss —epss 0.00
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used…
- risk 0.49cvss 7.5epss 0.01
An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having…
- risk 0.49cvss 7.5epss 0.01
Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance…
- risk 0.49cvss 7.6epss 0.01
A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.
- risk 0.49cvss 7.5epss 0.01
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
- risk 0.47cvss 7.2epss 0.01
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
- risk 0.47cvss —epss 0.00
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.
- risk 0.47cvss 7.2epss 0.04
Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.
- risk 0.46cvss 7.0epss 0.05
In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to…
- risk 0.44cvss —epss 0.00
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
- risk 0.44cvss 6.8epss 0.00
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on…
- risk 0.44cvss 6.8epss 0.01
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
Page 2 of 7