Vulnerability index

Browse CVEs

74 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zabbix HIGH 8.1
CVE-2026-23925

An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can le…

Fix: 6.0.41 / 7.0.18+
Fix from $1,950 2026-03-06
Frontend MEDIUM 6.5
CVE-2025-49643

An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to…

Fix: 6.0.42 / 7.0.19+
Fix from $1,600 2025-12-01
Zabbix MEDIUM 6.5
CVE-2025-27236

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows d…

Fix: 6.0.41 / 7.0.17+
Fix from $1,600 2025-10-03
Zabbix HIGH 7.2
CVE-2025-27240

A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.

Fix: 6.0.34 / 6.4.19+
Fix from $1,950 2025-09-12
Zabbix MEDIUM 6.5
CVE-2024-45700

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the se…

Fix: 6.0.39 / 7.0.10+
Fix from $1,600 2025-04-02
Zabbix MEDIUM 5.4
CVE-2024-45699

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the r…

Fix: 6.0.37 / 6.4.21+
Fix from $1,600 2025-04-02
Zabbix HIGH 8.8
CVE-2024-36465EPSS 26%

A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary…

Fix: 7.2.2+
Fix from $1,950 2025-04-02
Zabbix HIGH 8.8
CVE-2024-36466

A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.

Fix: 6.0.32 / 6.4.17+
Fix from $1,950 2024-11-28
Zabbix CRITICAL 9.1
CVE-2024-42330

The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings …

Fix: 5.4.6 / 6.0.34+
Fix from $2,300 2024-11-27
Zabbix CRITICAL 9.9
CVE-2024-42327EPSS 79%

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerabili…

Fix: 6.0.32 / 6.4.17+
Fix from $2,300 2024-11-27
Zabbix HIGH 8.2
CVE-2024-36468

The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix server/proxy code. This issue …

Fix: 7.0.3+
Fix from $1,950 2024-11-27
Zabbix MEDIUM 5.5
CVE-2024-42328

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb w…

Fix: 7.0.4+
Fix from $1,600 2024-11-27
Zabbix HIGH 8.8
CVE-2024-36467

An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is en…

Fix: 5.0.43 / 6.0.33+
Fix from $1,950 2024-11-27
Zabbix HIGH 8.8
CVE-2024-36463

The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.

Fix: 5.0.43 / 6.0.33+
Fix from $1,950 2024-11-26
Zabbix HIGH 8.8
CVE-2024-36461

Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

Fix: after 6.4.15
Fix from $1,950 2024-08-12
Zabbix HIGH 7.5
CVE-2024-36462

Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or net…

No fix yet
Fix from $1,950 2024-08-12
Zabbix HIGH 8.1
CVE-2024-36460

The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

Fix: after 6.4.15
Fix from $1,950 2024-08-12
Zabbix CRITICAL 9.1
CVE-2024-22122

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web …

Fix: after 6.4.15
Fix from $2,300 2024-08-12
Zabbix MEDIUM 6.1
CVE-2024-22121

A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the ap…

Fix: after 6.4.15
Fix from $1,600 2024-08-12
Zabbix HIGH 7.2
CVE-2024-22116

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default …

Fix: after 6.4.15
Fix from $1,950 2024-08-12
Zabbix HIGH 8.8
CVE-2024-22120EPSS 77%

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip"…

Fix: 6.0.28 / 6.4.13+
Fix from $1,950 2024-05-17
Zabbix MEDIUM 5.4
CVE-2024-22119

The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.

Fix: 5.0.40 / 6.0.24+
Fix from $1,600 2024-02-09
Zabbix Agent2 CRITICAL 9.8
CVE-2023-32728

The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability f…

Fix: after 6.4.8
Fix from $2,300 2023-12-18
Zabbix Server HIGH 8.8
CVE-2023-32725

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can t…

Fix: after 6.4.6
Fix from $1,950 2023-12-18
Zabbix Agent HIGH 8.1
CVE-2023-32726

The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.

Fix: after 6.4.8
Fix from $1,950 2023-12-18
Zabbix Server HIGH 7.2
CVE-2023-32727

An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitr…

Fix: after 6.4.7
Fix from $1,950 2023-12-18
Zabbix CRITICAL 9.1
CVE-2023-32723

Request to LDAP is sent before user permissions are checked.

Fix: 4.0.19 / 4.4.7+
Fix from $2,300 2023-10-12
Zabbix HIGH 8.8
CVE-2023-32724

Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.

Fix: after 6.4.5
Fix from $1,950 2023-10-12
Zabbix HIGH 7.8
CVE-2023-32722

The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.

Fix: after 6.4.5
Fix from $1,950 2023-10-12
Zabbix MEDIUM 5.4
CVE-2023-32721

A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.

Fix: after 6.4.5
Fix from $1,600 2023-10-12