VYPR

Vendor CVEs

Zabbix

All CVEs

128 total · sorted by risk
  • CVE-2020-15803MedJul 17, 2020
    risk 0.42cvss 6.1epss 0.32

    Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

  • CVE-2023-29457MedJul 13, 2023
    risk 0.41cvss 6.3epss 0.01

    Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts.

  • CVE-2023-29452MedJul 13, 2023
    risk 0.41cvss 5.5epss 0.64

    Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.

  • CVE-2022-23133MedJan 13, 2022
    risk 0.41cvss 6.3epss 0.01

    An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire…

  • CVE-2026-23924MedMar 24, 2026
    risk 0.40cvss epss 0.00

    Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.

  • CVE-2024-22121MedAug 12, 2024
    risk 0.40cvss 6.1epss 0.00

    A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.

  • CVE-2016-10742MedFeb 17, 2019
    risk 0.40cvss 6.1epss 0.03

    Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.

  • CVE-2025-49642MedDec 1, 2025
    risk 0.38cvss epss 0.00

    Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directory.

  • CVE-2023-29458MedJul 13, 2023
    risk 0.38cvss 5.9epss 0.01

    Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use.

  • CVE-2023-29449MedJul 13, 2023
    risk 0.38cvss 5.9epss 0.01

    JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should…

  • CVE-2025-27233MedSep 12, 2025
    risk 0.37cvss epss 0.00

    Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.

  • CVE-2023-29456MedJul 13, 2023
    risk 0.37cvss 5.7epss 0.01

    URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.

  • CVE-2024-22119MedFeb 9, 2024
    risk 0.36cvss 5.5epss 0.01

    The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.

  • CVE-2024-45699MedApr 2, 2025
    risk 0.35cvss 5.4epss 0.00

    The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be…

  • CVE-2023-29455MedJul 13, 2023
    risk 0.35cvss 5.4epss 0.01

    Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of…

  • CVE-2023-29454MedJul 13, 2023
    risk 0.35cvss 5.4epss 0.01

    Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the…

  • CVE-2022-43515MedDec 5, 2022
    risk 0.35cvss 5.3epss 0.01

    Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be…

  • CVE-2019-15132MedAug 17, 2019
    risk 0.35cvss 5.3epss 0.02

    Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just…

  • CVE-2026-23927MedMay 6, 2026
    risk 0.33cvss epss 0.00

    A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.

  • CVE-2025-27232MedDec 1, 2025
    risk 0.32cvss 4.9epss 0.00

    An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

  • CVE-2025-27231MedOct 3, 2025
    risk 0.32cvss 4.9epss 0.00

    The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind password' value is now reset on 'Host' change.

  • CVE-2023-30958MedAug 3, 2023
    risk 0.31cvss 4.7epss 0.00

    A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.225.0.

  • CVE-2023-29451MedJul 13, 2023
    risk 0.31cvss 4.7epss 0.01

    Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.

  • CVE-2022-40626MedSep 14, 2022
    risk 0.31cvss 4.8epss 0.01

    An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.

  • CVE-2023-32728MedDec 18, 2023
    risk 0.30cvss 4.6epss 0.01

    The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.

  • CVE-2022-24349MedMar 9, 2022
    risk 0.30cvss 4.6epss 0.01

    An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to…

  • CVE-2024-42326MedNov 27, 2024
    risk 0.29cvss 4.4epss 0.00

    There was discovered a use after free bug in browser.c in the es_browser_get_variant function

  • CVE-2025-49641MedOct 3, 2025
    risk 0.28cvss 4.3epss 0.00

    A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.

  • CVE-2024-22114MedAug 12, 2024
    risk 0.28cvss 4.3epss 0.01

    User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard.

  • CVE-2023-32726LowDec 18, 2023
    risk 0.25cvss 3.9epss 0.01

    The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.

  • CVE-2024-42332LowNov 27, 2024
    risk 0.24cvss 3.7epss 0.01

    The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with additional lines of information and have forged data show in the Zabbix UI. This attack requires SNMP auth to be off and/or the attacker to know the community/auth…

  • CVE-2022-35230LowJul 6, 2022
    risk 0.24cvss 3.7epss 0.01

    An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.

  • CVE-2022-35229LowJul 6, 2022
    risk 0.24cvss 3.7epss 0.01

    An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.

  • CVE-2022-24919LowMar 9, 2022
    risk 0.24cvss 3.7epss 0.01

    An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code…

  • CVE-2022-24918LowMar 9, 2022
    risk 0.24cvss 3.7epss 0.01

    An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code…

  • CVE-2022-24917LowMar 9, 2022
    risk 0.24cvss 3.7epss 0.01

    An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious…

  • CVE-2017-2826LowApr 9, 2018
    risk 0.24cvss 3.7epss 0.03

    An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker…

  • CVE-2025-27238LowSep 12, 2025
    risk 0.23cvss 3.5epss 0.00

    Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.

  • CVE-2024-42325LowApr 2, 2025
    risk 0.23cvss 3.5epss 0.00

    Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.

  • CVE-2022-23132LowJan 13, 2022
    risk 0.22cvss 3.3epss 0.01

    During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level

  • CVE-2024-42331LowNov 27, 2024
    risk 0.21cvss 3.3epss 0.00

    In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript engine. This heap pointer is subsequently utilized by the browser_push_error method in the src/libs/zbxembed/browser_error.c file. A use-after-free bug can…

  • CVE-2024-42329LowNov 27, 2024
    risk 0.21cvss 3.3epss 0.00

    The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function fails. But this function can fail for various reasons without an error description and then the wd->error will be NULL and trying to read from it will result…

  • CVE-2024-42328LowNov 27, 2024
    risk 0.21cvss 3.3epss 0.00

    When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt…

  • CVE-2024-36469LowApr 2, 2025
    risk 0.20cvss 3.1epss 0.00

    Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.

  • CVE-2024-36468LowNov 27, 2024
    risk 0.20cvss 3.0epss 0.01

    The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix server/proxy code. This issue occurs when copying data from session->securityEngineID to local_record.engineid without proper bounds checking.

  • CVE-2024-22122LowAug 12, 2024
    risk 0.20cvss 3.0epss 0.02

    Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT…

  • CVE-2024-36464LowNov 27, 2024
    risk 0.18cvss 2.7epss 0.01

    When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these…

  • CVE-2024-42333LowNov 27, 2024
    risk 0.18cvss 2.7epss 0.01

    The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read in src/libs/zbxmedia/email.c

  • CVE-2024-22123LowAug 12, 2024
    risk 0.18cvss 2.7epss 0.01

    Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken…

  • CVE-2024-22117LowNov 26, 2024
    risk 0.14cvss 2.2epss 0.00

    When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value…