VYPR

Vendor CVEs

Zabbix

All CVEs

128 total · sorted by risk
  • CVE-2022-23131CriKEVJan 13, 2022
    risk 0.79cvss 9.1epss 0.96

    In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and…

  • CVE-2013-5743CriDec 11, 2019
    risk 0.73cvss 9.8epss 0.80

    Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

  • CVE-2016-10134CriFeb 17, 2017
    risk 0.73cvss 9.8epss 0.83

    SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

  • CVE-2024-42327CriNov 27, 2024
    risk 0.67cvss 9.9epss 0.79

    A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function…

  • CVE-2013-3628HigFeb 7, 2020
    risk 0.66cvss 8.8epss 0.67

    Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

  • CVE-2024-22120CriMay 17, 2024
    risk 0.65cvss 9.1epss 0.77

    Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

  • CVE-2024-22116CriAug 12, 2024
    risk 0.64cvss 9.9epss 0.02

    An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising…

  • CVE-2023-29453CriOct 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the…

  • CVE-2022-22704CriJan 6, 2022
    risk 0.64cvss 9.8epss 0.01

    The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.

  • CVE-2020-11800CriOct 7, 2020
    risk 0.64cvss 9.8epss 0.09

    Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.

  • CVE-2013-3738CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.

  • CVE-2014-3005CriFeb 1, 2018
    risk 0.64cvss 9.8epss 0.05

    XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.

  • CVE-2019-17382CriOct 9, 2019
    risk 0.63cvss 9.1epss 0.54

    An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All…

  • CVE-2023-32725CriDec 18, 2023
    risk 0.62cvss 9.6epss 0.01

    The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

  • CVE-2023-32722CriOct 12, 2023
    risk 0.62cvss 9.6epss 0.01

    The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.

  • CVE-2024-36465HigApr 2, 2025
    risk 0.59cvss 8.8epss 0.26

    A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.

  • CVE-2024-42330CriNov 27, 2024
    risk 0.59cvss 9.1epss 0.01

    The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create…

  • CVE-2024-36461CriAug 12, 2024
    risk 0.59cvss 9.1epss 0.01

    Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

  • CVE-2023-32724CriOct 12, 2023
    risk 0.59cvss 9.1epss 0.01

    Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.

  • CVE-2026-23921HigMar 24, 2026
    risk 0.57cvss epss 0.00

    A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary…

  • CVE-2024-36466HigNov 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.

  • CVE-2021-27927HigMar 3, 2021
    risk 0.57cvss 8.8epss 0.01

    In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the…

  • CVE-2016-4338HigJan 23, 2017
    risk 0.57cvss 8.1epss 0.21

    The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via…

  • CVE-2023-32723HigOct 12, 2023
    risk 0.55cvss 8.5epss 0.01

    Request to LDAP is sent before user permissions are checked.

  • CVE-2023-29450HigJul 13, 2023
    risk 0.55cvss 8.5epss 0.01

    JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

  • CVE-2017-2824HigMay 24, 2017
    risk 0.55cvss 8.1epss 0.26

    An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to…

  • CVE-2026-23925HigMar 6, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit…

  • CVE-2024-36460HigAug 12, 2024
    risk 0.53cvss 8.1epss 0.01

    The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

  • CVE-2026-23920HigMar 24, 2026
    risk 0.50cvss epss 0.00

    Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.

  • CVE-2024-36467HigNov 27, 2024
    risk 0.49cvss 7.5epss 0.01

    An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having…

  • CVE-2024-36462HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance…

  • CVE-2023-32721HigOct 12, 2023
    risk 0.49cvss 7.6epss 0.01

    A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.

  • CVE-2013-7484HigNov 30, 2019
    risk 0.49cvss 7.5epss 0.01

    Zabbix before 5.0 represents passwords in the users table with unsalted MD5.

  • CVE-2026-23928HigMay 6, 2026
    risk 0.47cvss epss 0.00

    The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The…

  • CVE-2026-23926HigMay 6, 2026
    risk 0.47cvss epss 0.00

    An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on…

  • CVE-2025-27237HigOct 3, 2025
    risk 0.47cvss epss 0.00

    In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.

  • CVE-2025-27240HigSep 12, 2025
    risk 0.47cvss 7.2epss 0.01

    A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.

  • CVE-2025-27234HigSep 12, 2025
    risk 0.47cvss epss 0.00

    Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.

  • CVE-2021-46088HigJan 27, 2022
    risk 0.47cvss 7.2epss 0.04

    Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.

  • CVE-2026-23919HigMar 24, 2026
    risk 0.46cvss epss 0.00

    For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A…

  • CVE-2017-2825HigApr 20, 2018
    risk 0.46cvss 7.0epss 0.04

    In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to…

  • CVE-2026-23923MedMar 24, 2026
    risk 0.45cvss epss 0.00

    An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

  • CVE-2023-32727MedDec 18, 2023
    risk 0.44cvss 6.8epss 0.01

    An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.

  • CVE-2022-23134LowKEVJan 13, 2022
    risk 0.43cvss 3.7epss 0.85

    After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

  • CVE-2025-49643MedDec 1, 2025
    risk 0.42cvss 6.5epss 0.00

    An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.

  • CVE-2025-27236MedOct 3, 2025
    risk 0.42cvss 6.5epss 0.00

    A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.

  • CVE-2024-45700MedApr 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations,…

  • CVE-2024-36463MedNov 26, 2024
    risk 0.42cvss 6.5epss 0.01

    The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.

  • CVE-2022-46768MedDec 15, 2022
    risk 0.42cvss 5.9epss 0.48

    Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.

  • CVE-2022-43516MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.01

    A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI)

Page 1 of 3