VYPR

Zabbix

by Zabbix

Source repositories

CVEs (121)

  • CVE-2022-23134LowKEVJan 13, 2022
    risk 0.43cvss 3.7epss 0.85

    After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

  • CVE-2025-49643MedDec 1, 2025
    risk 0.42cvss 6.5epss 0.00

    An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.

  • CVE-2025-27236MedOct 3, 2025
    risk 0.42cvss 6.5epss 0.00

    A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.

  • CVE-2024-45700MedApr 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations,…

  • CVE-2024-36463MedNov 26, 2024
    risk 0.42cvss 6.5epss 0.01

    The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.

  • CVE-2022-46768MedDec 15, 2022
    risk 0.42cvss 5.9epss 0.48

    Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.

  • CVE-2022-43516MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.01

    A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI)

  • CVE-2020-15803MedJul 17, 2020
    risk 0.42cvss 6.1epss 0.32

    Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

  • CVE-2023-29457MedJul 13, 2023
    risk 0.41cvss 6.3epss 0.01

    Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts.

  • CVE-2023-29452MedJul 13, 2023
    risk 0.41cvss 5.5epss 0.64

    Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.

  • CVE-2022-23133MedJan 13, 2022
    risk 0.41cvss 6.3epss 0.01

    An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire…

  • CVE-2026-23924MedMar 24, 2026
    risk 0.40cvss epss 0.00

    Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.

  • CVE-2024-22121MedAug 12, 2024
    risk 0.40cvss 6.1epss 0.00

    A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.

  • CVE-2016-10742MedFeb 17, 2019
    risk 0.40cvss 6.1epss 0.03

    Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.

  • CVE-2023-29458MedJul 13, 2023
    risk 0.38cvss 5.9epss 0.01

    Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use.

  • CVE-2023-29449MedJul 13, 2023
    risk 0.38cvss 5.9epss 0.01

    JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should…

  • CVE-2023-29456MedJul 13, 2023
    risk 0.37cvss 5.7epss 0.01

    URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.

  • CVE-2024-22119MedFeb 9, 2024
    risk 0.36cvss 5.5epss 0.01

    The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.

  • CVE-2024-45699MedApr 2, 2025
    risk 0.35cvss 5.4epss 0.00

    The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be…

  • CVE-2023-29455MedJul 13, 2023
    risk 0.35cvss 5.4epss 0.01

    Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of…

Page 3 of 7