Vulnerabilidades en Zabbix

94 resultados
Análisis Vexday

O Zabbix apresenta uma taxa de exploração ativa 5,4 vezes acima da média geral do catálogo CISA KEV, o que indica risco operacional elevado em relação ao volume total de CVEs catalogadas. O pior caso ativo, CVE-2022-23131, registra EPSS de 0,9568 — valor que sinaliza altíssima probabilidade de exploração observada na prática — e deve ser tratado como prioridade imediata de remediação. Das 83 CVEs catalogadas, 10 são de severidade crítica e 5 possuem PoC pública disponível, ampliando a superfície de exposição para atores com capacidade técnica limitada. A falha mais recorrente (CWE-20, validação inadequada de entrada) e o surgimento de 3 novas CVEs nos últimos 90 dias reforçam a necessidade de monitoramento contínuo e ciclos curtos de atualização para ambientes que operam esta plataforma.

CVE-2023-32726LOWPossible buffer overread from reading DNS responsesEPSS 0.7%CVE-2024-42333LOWHeap buffer over-readEPSS 0.6%CVE-2024-42332LOWNew line injection in Zabbix SNMP trapsEPSS 0.6%CVE-2024-36460HIGHFront-end audit log shows passwords in plaintextEPSS 0.6%CVE-2023-29455MEDIUMReflected XSS in several fields of graph formEPSS 0.6%CVE-2023-32721HIGHStored XSS in Maps elementEPSS 0.6%CVE-2023-32724CRITICALJavaScript engine memory pointers are directly available for Zabbix users for modificationEPSS 0.6%CVE-2024-22114MEDIUMSystem Information Widget in Global View Dashboard exposes information about Hosts to Users without PermissionEPSS 0.6%CVE-2023-29454MEDIUMPersistent XSS in the user formEPSS 0.6%CVE-2024-22123LOWZabbix Arbitrary File ReadEPSS 0.6%CVE-2023-29457MEDIUMInsufficient validation of Action form input fieldsEPSS 0.6%CVE-2023-32723HIGHInefficient permission check in class CControllerAuthenticationUpdateEPSS 0.6%CVE-2024-36464LOWMedia Types: Office365, SMTP passwords are unencrypted and visible in plaintext when exportedEPSS 0.6%CVE-2023-29456MEDIUMInefficient URL schema validationEPSS 0.6%CVE-2024-36468LOWStack buffer overflow in zbx_snmp_cache_handle_engineidEPSS 0.5%CVE-2024-22117LOWValue of sysmap_element_url can be de-synchronized causing the map element to crash when new URLs is addedEPSS 0.5%CVE-2025-27231MEDIUMLDAP 'Bind password' field value can be leaked by a Zabbix Super AdminEPSS 0.5%CVE-2025-27236LOWUser information disclosure via api_jsonrpc.php on method user.get with param searchEPSS 0.4%CVE-2026-23930MEDIUMFrontend DoS via the popup.testtriggerexpr actionEPSS 0.4%CVE-2024-45699HIGHReflected XSS vulnerability in /zabbix.php?action=export.valuemapsEPSS 0.4%