Exposición de Zabbix

Miscellaneous
21
score de exposición
4
sitios usan
0
en explotación
9
críticos
Análisis Vexday

Com 70 CVEs catalogadas, o Zabbix apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de uso malicioso ativo no momento. No entanto, a ausência de exploração confirmada não elimina o risco: CVE-2024-42327 concentra um escore EPSS de 0,7883, indicando probabilidade elevada de exploração futura segundo modelos preditivos. O tipo de falha mais recorrente é CWE-20 (validação imprópria de entrada), padrão que historicamente facilita encadeamento de vulnerabilidades em plataformas de monitoramento com amplo acesso à infraestrutura. Com 9 CVEs críticas no total e 3 surgidas nos últimos 90 dias, equipes que operam Zabbix em ambientes expostos devem priorizar a aplicação de patches recentes e monitorar ativamente CVE-2024-42327.

CVEs

70 resultados
CVE-2024-42327CRITICALSQL injection in user.get APIEPSS 78.8%CVE-2024-22120CRITICALTime Based SQL Injection in Zabbix Server Audit LogEPSS 76.6%CVE-2013-3628Zabbix 2.0.9 has an Arbitrary Command Execution VulnerabilityEPSS 67.5%CVE-2023-29452MEDIUMRemove possibility to add html into Geomap attribution fieldEPSS 64.1%CVE-2024-36465HIGHSQL injection in Zabbix APIEPSS 26.5%CVE-2017-2825In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in databEPSS 4.4%CVE-2017-2826An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy requesEPSS 3.4%CVE-2024-22122LOWAT(GSM) Command InjectionEPSS 1.6%CVE-2024-22116CRITICALRemote code execution within ping scriptEPSS 1.6%CVE-2023-29450HIGHUnauthorized limited filesystem access from preprocessingEPSS 1.3%CVE-2025-27240HIGHSecondary-order SQL injection in Zabbix Server when deleting an autoregistered hostEPSS 1.2%CVE-2023-29449MEDIUMLimited control of resource utilization in JS preprocessingEPSS 1.2%CVE-2024-42330CRITICALJS - Internal strings in HTTP headersEPSS 1.0%CVE-2024-36462HIGHAllocation of resources without limits or throttling (uncontrolled resource consumption)EPSS 0.9%CVE-2023-32727MEDIUMCode execution vulnerability in icmppingEPSS 0.9%CVE-2023-32725CRITICALLeak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.EPSS 0.8%CVE-2024-36463MEDIUMThe implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objecEPSS 0.8%CVE-2023-29451MEDIUMDenial of service caused by a bug in the JSON parserEPSS 0.8%CVE-2023-29458MEDIUMDuktape 2.6 bug crashes JavaScript putting too many values in valstack.EPSS 0.8%CVE-2024-36461CRITICALDirect access to memory pointers within the JS engine for modificationEPSS 0.8%