CVEs we hold for Zabbix
Records whose assigning authority named Zabbix as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-59781Improper validation of custom installation directories on Windows could allow installation into locations with unsafe…Zabbix CVE-2026-23938Server DoS via JavaScript preprocessing or script itemsZabbix CVE-2026-23935Use-after-free read in script item/preprocessing HttpRequest bodyZabbix CVE-2026-23931Frontend plaintext macro value enumeration via the validatate.api.exists actionZabbix CVE-2026-23928Stored XSS vulnerability in the Item history/Plain text widgetZabbix CVE-2026-23927Agent 2 Oracle plugin TNS connection string injection via the 'service' parameterZabbix CVE-2026-23926Stored XSS vulnerability in Host navigator widget maintenance tooltipZabbix CVE-2026-23925Unauthorized host creation via configuration.import API by low-privilege user with write permissionsZabbix CVE-2026-23924Agent 2 Docker plugin arbitrary file read via Docker API injectionZabbix CVE-2026-23921Blind, read-only SQL injection in Zabbix API via sortfield parameterZabbix CVE-2026-23920Host and event action script regex validation can be bypassed in certain situations, leading to potential command…Zabbix CVE-2026-23919Insufficient isolation of JavaScript (Duktape) execution context on Zabbix ServerZabbix CVE-2025-49643Frontend DoS vulnerability due to asymmetric resource consumptionZabbix CVE-2025-49642Agent builds for AIX vulnerable to library loading hijackingZabbix CVE-2025-49641Insufficient permission check for the problem.view.refresh actionZabbix CVE-2025-27240Secondary-order SQL injection in Zabbix Server when deleting an autoregistered hostZabbix CVE-2025-27238API hostprototype.get lists data to users with insufficient authorization.Zabbix CVE-2025-27237DLL injection in Zabbix Agent and Agent 2 via OpenSSL configurationZabbix CVE-2025-27236User information disclosure via api_jsonrpc.php on method user.get with param searchZabbix CVE-2025-27234Zabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0.Zabbix CVE-2025-27233Zabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later.Zabbix CVE-2025-27232Frontend arbitrary file read in oauth.authorize actionZabbix CVE-2025-27231LDAP 'Bind password' field value can be leaked by a Zabbix Super AdminZabbix CVE-2024-45700DoS vulnerability due to uncontrolled resource exhaustionZabbix CVE-2024-45699Reflected XSS vulnerability in /zabbix.php?action=export.valuemapsZabbix CVE-2024-36469User enumeration via timing attack in Zabbix web interfaceZabbix CVE-2024-36468Stack buffer overflow in zbx_snmp_cache_handle_engineidZabbix CVE-2024-36467Authentication privilege escalation via user groups due to missing authorization checksZabbix CVE-2024-36466Unauthenticated Zabbix frontend takeover when SSO is being usedZabbix CVE-2024-36464Media Types: Office365, SMTP passwords are unencrypted and visible in plaintext when exportedZabbix CVE-2024-36462Allocation of resources without limits or throttling (uncontrolled resource consumption)Zabbix CVE-2024-36461Direct access to memory pointers within the JS engine for modificationZabbix CVE-2024-22121Zabbix Agent MSI Installer Allows Non-Admin User to Access Change Option via msiexec.exeZabbix CVE-2024-22120Time Based SQL Injection in Zabbix Server Audit LogZabbix CVE-2024-22117Value of sysmap_element_url can be de-synchronized causing the map element to crash when new URLs is addedZabbix CVE-2024-22114System Information Widget in Global View Dashboard exposes information about Hosts to Users without PermissionZabbix CVE-2023-32728Code injection in zabbix_agent2 smart.disk.get caused by smartctl pluginZabbix CVE-2023-32726Possible buffer overread from reading DNS responsesZabbix CVE-2023-32725Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.Zabbix CVE-2023-32724JavaScript engine memory pointers are directly available for Zabbix users for modificationZabbix CVE-2023-32723Inefficient permission check in class CControllerAuthenticationUpdateZabbix CVE-2023-29458Duktape 2.6 bug crashes JavaScript putting too many values in valstack.Zabbix CVE-2023-29457Insufficient validation of Action form input fieldsZabbix CVE-2023-29453Agent 2 package are built with Go version affected by CVE-2023-24538Zabbix CVE-2023-29452Remove possibility to add html into Geomap attribution fieldZabbix CVE-2023-29451Denial of service caused by a bug in the JSON parserZabbix CVE-2023-29450Unauthorized limited filesystem access from preprocessingZabbix CVE-2023-29449Limited control of resource utilization in JS preprocessingZabbix CVE-2022-46768File name information disclosure vulnerability in Zabbix Web Service Report GenerationZabbix agent 2 (MSI packages) CVE-2022-43516Zabbix Agent installer adds “allow all TCP any any” firewall ruleZabbix agent 2 (MSI packages) CVE-2022-43515X-Forwarded-For header is active by default causes access to Zabbix sites in maintenance modeZabbix Frontend CVE-2022-40626Reflected XSS in the backurl parameter of Zabbix FrontendZabbix Frontend CVE-2022-35230Reflected XSS in graphs page of Zabbix FrontendZabbix Frontend CVE-2022-35229Reflected XSS in discovery page of Zabbix FrontendZabbix Frontend CVE-2022-24919Reflected XSS in graph configuration window of Zabbix FrontendZabbix Frontend CVE-2022-24918Reflected XSS in item configuration window of Zabbix FrontendZabbix Frontend CVE-2022-24917Reflected XSS in service configuration window of Zabbix FrontendZabbix Frontend CVE-2022-24349Reflected XSS in action configuration window of Zabbix FrontendZabbix Frontend CVE-2022-23134Possible view of the setup pages by unauthenticated users if config file already existsZabbix Frontend CVE-2022-23133Stored XSS in host groups configuration window in Zabbix FrontendZabbix Frontend CVE-2022-23132Incorrect permissions of [/var/run/zabbix] forces dac_overrideZabbix Proxy, Server CVE-2022-23131Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with…Zabbix Frontend 94 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.