vciy

CVEs we hold for Zabbix

Records whose assigning authority named Zabbix as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-59781Improper validation of custom installation directories on Windows could allow installation into locations with unsafe…Zabbix
CVE-2026-23938Server DoS via JavaScript preprocessing or script itemsZabbix
CVE-2026-23937Host PSK extraction in Zabbix APIZabbix
CVE-2026-23935Use-after-free read in script item/preprocessing HttpRequest bodyZabbix
CVE-2026-23934Frontend DoS via the validate.api.exists actionZabbix
CVE-2026-23933Hardcoded session key in Zabbix 7.4Zabbix
CVE-2026-23931Frontend plaintext macro value enumeration via the validatate.api.exists actionZabbix
CVE-2026-23930Frontend DoS via the popup.testtriggerexpr actionZabbix
CVE-2026-23929Prototype pollution leading to stored XSSZabbix
CVE-2026-23928Stored XSS vulnerability in the Item history/Plain text widgetZabbix
CVE-2026-23927Agent 2 Oracle plugin TNS connection string injection via the 'service' parameterZabbix
CVE-2026-23926Stored XSS vulnerability in Host navigator widget maintenance tooltipZabbix
CVE-2026-23925Unauthorized host creation via configuration.import API by low-privilege user with write permissionsZabbix
CVE-2026-23924Agent 2 Docker plugin arbitrary file read via Docker API injectionZabbix
CVE-2026-23923Unauthenticated arbitrary PHP class instantiationZabbix
CVE-2026-23922Email media OAuth secret leak to Super AdminZabbix
CVE-2026-23921Blind, read-only SQL injection in Zabbix API via sortfield parameterZabbix
CVE-2026-23920Host and event action script regex validation can be bypassed in certain situations, leading to potential command…Zabbix
CVE-2026-23919Insufficient isolation of JavaScript (Duktape) execution context on Zabbix ServerZabbix
CVE-2026-1199API and Frontend login lockout race conditionZabbix
CVE-2025-49643Frontend DoS vulnerability due to asymmetric resource consumptionZabbix
CVE-2025-49642Agent builds for AIX vulnerable to library loading hijackingZabbix
CVE-2025-49641Insufficient permission check for the problem.view.refresh actionZabbix
CVE-2025-27240Secondary-order SQL injection in Zabbix Server when deleting an autoregistered hostZabbix
CVE-2025-27238API hostprototype.get lists data to users with insufficient authorization.Zabbix
CVE-2025-27237DLL injection in Zabbix Agent and Agent 2 via OpenSSL configurationZabbix
CVE-2025-27236User information disclosure via api_jsonrpc.php on method user.get with param searchZabbix
CVE-2025-27234Zabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0.Zabbix
CVE-2025-27233Zabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later.Zabbix
CVE-2025-27232Frontend arbitrary file read in oauth.authorize actionZabbix
CVE-2025-27231LDAP 'Bind password' field value can be leaked by a Zabbix Super AdminZabbix
CVE-2024-45700DoS vulnerability due to uncontrolled resource exhaustionZabbix
CVE-2024-45699Reflected XSS vulnerability in /zabbix.php?action=export.valuemapsZabbix
CVE-2024-42333Heap buffer over-readZabbix
CVE-2024-42332New line injection in Zabbix SNMP trapsZabbix
CVE-2024-42331Use after free in browser_push_errorZabbix
CVE-2024-42330JS - Internal strings in HTTP headersZabbix
CVE-2024-42329JS - Crash on unexpected HTTP server responseZabbix
CVE-2024-42328JS - Crash on empty HTTP server responseZabbix
CVE-2024-42327SQL injection in user.get APIZabbix
CVE-2024-42326Use after free vulnerability in browser.cZabbix
CVE-2024-42325Excessive information returned by user.getZabbix
CVE-2024-36469User enumeration via timing attack in Zabbix web interfaceZabbix
CVE-2024-36468Stack buffer overflow in zbx_snmp_cache_handle_engineidZabbix
CVE-2024-36467Authentication privilege escalation via user groups due to missing authorization checksZabbix
CVE-2024-36466Unauthenticated Zabbix frontend takeover when SSO is being usedZabbix
CVE-2024-36465SQL injection in Zabbix APIZabbix
CVE-2024-36464Media Types: Office365, SMTP passwords are unencrypted and visible in plaintext when exportedZabbix
CVE-2024-36463no title heldZabbix
CVE-2024-36462Allocation of resources without limits or throttling (uncontrolled resource consumption)Zabbix
CVE-2024-36461Direct access to memory pointers within the JS engine for modificationZabbix
CVE-2024-36460Front-end audit log shows passwords in plaintextZabbix
CVE-2024-22123Zabbix Arbitrary File ReadZabbix
CVE-2024-22122AT(GSM) Command InjectionZabbix
CVE-2024-22121Zabbix Agent MSI Installer Allows Non-Admin User to Access Change Option via msiexec.exeZabbix
CVE-2024-22120Time Based SQL Injection in Zabbix Server Audit LogZabbix
CVE-2024-22119Stored XSS in graph items select formZabbix
CVE-2024-22117Value of sysmap_element_url can be de-synchronized causing the map element to crash when new URLs is addedZabbix
CVE-2024-22116Remote code execution within ping scriptZabbix
CVE-2024-22114System Information Widget in Global View Dashboard exposes information about Hosts to Users without PermissionZabbix
CVE-2023-32728Code injection in zabbix_agent2 smart.disk.get caused by smartctl pluginZabbix
CVE-2023-32727Code execution vulnerability in icmppingZabbix
CVE-2023-32726Possible buffer overread from reading DNS responsesZabbix
CVE-2023-32725Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.Zabbix
CVE-2023-32724JavaScript engine memory pointers are directly available for Zabbix users for modificationZabbix
CVE-2023-32723Inefficient permission check in class CControllerAuthenticationUpdateZabbix
CVE-2023-32722Stack-buffer Overflow in library module zbxjsonZabbix
CVE-2023-32721Stored XSS in Maps elementZabbix
CVE-2023-29458Duktape 2.6 bug crashes JavaScript putting too many values in valstack.Zabbix
CVE-2023-29457Insufficient validation of Action form input fieldsZabbix
CVE-2023-29456Inefficient URL schema validationZabbix
CVE-2023-29455Reflected XSS in several fields of graph formZabbix
CVE-2023-29454Persistent XSS in the user formZabbix
CVE-2023-29453Agent 2 package are built with Go version affected by CVE-2023-24538Zabbix
CVE-2023-29452Remove possibility to add html into Geomap attribution fieldZabbix
CVE-2023-29451Denial of service caused by a bug in the JSON parserZabbix
CVE-2023-29450Unauthorized limited filesystem access from preprocessingZabbix
CVE-2023-29449Limited control of resource utilization in JS preprocessingZabbix
CVE-2022-46768File name information disclosure vulnerability in Zabbix Web Service Report GenerationZabbix agent 2 (MSI packages)
CVE-2022-43516Zabbix Agent installer adds “allow all TCP any any” firewall ruleZabbix agent 2 (MSI packages)
CVE-2022-43515X-Forwarded-For header is active by default causes access to Zabbix sites in maintenance modeZabbix Frontend
CVE-2022-40626Reflected XSS in the backurl parameter of Zabbix FrontendZabbix Frontend
CVE-2022-35230Reflected XSS in graphs page of Zabbix FrontendZabbix Frontend
CVE-2022-35229Reflected XSS in discovery page of Zabbix FrontendZabbix Frontend
CVE-2022-24919Reflected XSS in graph configuration window of Zabbix FrontendZabbix Frontend
CVE-2022-24918Reflected XSS in item configuration window of Zabbix FrontendZabbix Frontend
CVE-2022-24917Reflected XSS in service configuration window of Zabbix FrontendZabbix Frontend
CVE-2022-24349Reflected XSS in action configuration window of Zabbix FrontendZabbix Frontend
CVE-2022-23134Possible view of the setup pages by unauthenticated users if config file already existsZabbix Frontend
CVE-2022-23133Stored XSS in host groups configuration window in Zabbix FrontendZabbix Frontend
CVE-2022-23132Incorrect permissions of [/var/run/zabbix] forces dac_overrideZabbix Proxy, Server
CVE-2022-23131Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with…Zabbix Frontend
CVE-2017-2824no title heldZabbix Server
CVE-2013-3628no title heldZabbix

94 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.