Vulnerabilities in Zabbix

94 results
Vexday analysis

O Zabbix apresenta uma taxa de exploração ativa 5,4 vezes acima da média geral do catálogo CISA KEV, o que indica risco operacional elevado em relação ao volume total de CVEs catalogadas. O pior caso ativo, CVE-2022-23131, registra EPSS de 0,9568 — valor que sinaliza altíssima probabilidade de exploração observada na prática — e deve ser tratado como prioridade imediata de remediação. Das 83 CVEs catalogadas, 10 são de severidade crítica e 5 possuem PoC pública disponível, ampliando a superfície de exposição para atores com capacidade técnica limitada. A falha mais recorrente (CWE-20, validação inadequada de entrada) e o surgimento de 3 novas CVEs nos últimos 90 dias reforçam a necessidade de monitoramento contínuo e ciclos curtos de atualização para ambientes que operam esta plataforma.

CVE-2022-23133MEDIUMStored XSS in host groups configuration window in Zabbix FrontendEPSS 1.0%CVE-2022-43516MEDIUMZabbix Agent installer adds “allow all TCP any any” firewall ruleEPSS 0.9%CVE-2024-36462HIGHAllocation of resources without limits or throttling (uncontrolled resource consumption)EPSS 0.9%CVE-2024-42330CRITICALJS - Internal strings in HTTP headersEPSS 0.9%CVE-2023-32727MEDIUMCode execution vulnerability in icmppingEPSS 0.9%CVE-2023-32725CRITICALLeak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.EPSS 0.8%CVE-2024-36463MEDIUMThe implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objecEPSS 0.8%CVE-2022-35229LOWReflected XSS in discovery page of Zabbix FrontendEPSS 0.8%CVE-2022-23132LOWIncorrect permissions of [/var/run/zabbix] forces dac_overrideEPSS 0.8%CVE-2022-40626MEDIUMReflected XSS in the backurl parameter of Zabbix FrontendEPSS 0.8%CVE-2022-35230LOWReflected XSS in graphs page of Zabbix FrontendEPSS 0.8%CVE-2023-29451MEDIUMDenial of service caused by a bug in the JSON parserEPSS 0.8%CVE-2023-29458MEDIUMDuktape 2.6 bug crashes JavaScript putting too many values in valstack.EPSS 0.8%CVE-2024-36461CRITICALDirect access to memory pointers within the JS engine for modificationEPSS 0.8%CVE-2023-32728MEDIUMCode injection in zabbix_agent2 smart.disk.get caused by smartctl pluginEPSS 0.8%CVE-2023-29453CRITICALAgent 2 package are built with Go version affected by CVE-2023-24538EPSS 0.8%CVE-2024-22119MEDIUMStored XSS in graph items select formEPSS 0.7%CVE-2024-36466HIGHUnauthenticated Zabbix frontend takeover when SSO is being usedEPSS 0.7%CVE-2024-36467HIGHAuthentication privilege escalation via user groups due to missing authorization checksEPSS 0.7%CVE-2023-32722CRITICALStack-buffer Overflow in library module zbxjsonEPSS 0.7%