Skip to main content

Vendor archive

zabbix CVEs

Beta · best-effort

116 CVEs tagged to vendor zabbix19 Critical, 26 High, 46 Medium, 25 Low, 0 Unrated.

CVE-2026-23925

Published Mar 6, 2026

An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49643

Published Dec 1, 2025

An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to pot…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27232

Published Dec 1, 2025

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49641

Published Oct 3, 2025

A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active pro…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27236

Published Oct 3, 2025

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values t…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27231

Published Oct 3, 2025

The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind passw…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27240

Published Sep 12, 2025

A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27238

Published Sep 12, 2025

Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-45700

Published Apr 2, 2025

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the ser…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45699

Published Apr 2, 2025

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied dat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42325

Published Apr 2, 2025

Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-36469

Published Apr 2, 2025

Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-36465

Published Apr 2, 2025

A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36466

Published Nov 28, 2024

A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-36464

Published Nov 27, 2024

When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need t…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42333

Published Nov 27, 2024

The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read in src/libs/zbxmedia/email.c

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42332

Published Nov 27, 2024

The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with additional lines of information and have forged data show in the…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42331

Published Nov 27, 2024

In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript engine. This heap pointer is subsequently utilized by the…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42330

Published Nov 27, 2024

The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-42329

Published Nov 27, 2024

The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function fails. But this function can fail for various reasons with…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42328

Published Nov 27, 2024

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the ser…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42327

Published Nov 27, 2024

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUse…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-42326

Published Nov 27, 2024

There was discovered a use after free bug in browser.c in the es_browser_get_variant function

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36468

Published Nov 27, 2024

The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix server/proxy code. This issue occurs when copying data from…

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-36467

Published Nov 27, 2024

An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themsel…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 116 CVEsPage 1 of 5