Vulnerabilities in Zabbix

94 results
Vexday analysis

O Zabbix apresenta uma taxa de exploração ativa 5,4 vezes acima da média geral do catálogo CISA KEV, o que indica risco operacional elevado em relação ao volume total de CVEs catalogadas. O pior caso ativo, CVE-2022-23131, registra EPSS de 0,9568 — valor que sinaliza altíssima probabilidade de exploração observada na prática — e deve ser tratado como prioridade imediata de remediação. Das 83 CVEs catalogadas, 10 são de severidade crítica e 5 possuem PoC pública disponível, ampliando a superfície de exposição para atores com capacidade técnica limitada. A falha mais recorrente (CWE-20, validação inadequada de entrada) e o surgimento de 3 novas CVEs nos últimos 90 dias reforçam a necessidade de monitoramento contínuo e ciclos curtos de atualização para ambientes que operam esta plataforma.

CVE-2024-45700MEDIUMDoS vulnerability due to uncontrolled resource exhaustionEPSS 0.3%CVE-2025-49643MEDIUMFrontend DoS vulnerability due to asymmetric resource consumptionEPSS 0.3%CVE-2025-27237HIGHDLL injection in Zabbix Agent and Agent 2 via OpenSSL configurationEPSS 0.3%CVE-2024-36469LOWUser enumeration via timing attack in Zabbix web interfaceEPSS 0.3%CVE-2026-23937MEDIUMHost PSK extraction in Zabbix APIEPSS 0.3%CVE-2025-27234HIGHZabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0.EPSS 0.3%CVE-2026-23938LOWServer DoS via JavaScript preprocessing or script itemsEPSS 0.3%CVE-2026-23920HIGHHost and event action script regex validation can be bypassed in certain situations, leading to potential command injectionEPSS 0.3%CVE-2024-42325LOWExcessive information returned by user.getEPSS 0.3%CVE-2025-49641MEDIUMInsufficient permission check for the problem.view.refresh actionEPSS 0.3%CVE-2025-27232MEDIUMFrontend arbitrary file read in oauth.authorize actionEPSS 0.3%CVE-2026-23931MEDIUMFrontend plaintext macro value enumeration via the validatate.api.exists actionEPSS 0.3%CVE-2026-23922LOWEmail media OAuth secret leak to Super AdminEPSS 0.3%CVE-2026-23923MEDIUMUnauthenticated arbitrary PHP class instantiationEPSS 0.3%CVE-2026-23928HIGHStored XSS vulnerability in the Item history/Plain text widgetEPSS 0.3%CVE-2026-23926HIGHStored XSS vulnerability in Host navigator widget maintenance tooltipEPSS 0.3%CVE-2024-42331LOWUse after free in browser_push_errorEPSS 0.3%CVE-2026-23925MEDIUMUnauthorized host creation via configuration.import API by low-privilege user with write permissionsEPSS 0.3%CVE-2024-42329LOWJS - Crash on unexpected HTTP server responseEPSS 0.2%CVE-2026-23919HIGHInsufficient isolation of JavaScript (Duktape) execution context on Zabbix ServerEPSS 0.2%