CVE-2013-3628: vulnerability in Zabbix
Published · Updated
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 67%
from disclosure to weapon0 days
Published on NVDFeb 7
1st PoCOct 31
metasploitOct 30
exploitation probability
67%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
Affected products
Zabbix · Zabbixpublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/29321cve_referencewww.exploit-db.com/exploits/29321unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Zabbix
In the same product, most dangerous first.
CVE-2024-42327CRITICALSQL injection in user.get APIEPSS 78.7%CVE-2024-22120CRITICALTime Based SQL Injection in Zabbix Server Audit LogEPSS 76.6%CVE-2023-29452MEDIUMRemove possibility to add html into Geomap attribution fieldEPSS 64.1%CVE-2024-36465HIGHSQL injection in Zabbix APIEPSS 39.9%CVE-2026-23921HIGHBlind, read-only SQL injection in Zabbix API via sortfield parameterEPSS 3.9%CVE-2024-22122LOWAT(GSM) Command InjectionEPSS 1.6%