Exposição de Zabbix

Miscellaneous
29
score de exposição
6
sites usam
0
em exploração
9
críticos
Análise Vexday

Com 70 CVEs catalogadas, o Zabbix apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de uso malicioso ativo no momento. No entanto, a ausência de exploração confirmada não elimina o risco: CVE-2024-42327 concentra um escore EPSS de 0,7883, indicando probabilidade elevada de exploração futura segundo modelos preditivos. O tipo de falha mais recorrente é CWE-20 (validação imprópria de entrada), padrão que historicamente facilita encadeamento de vulnerabilidades em plataformas de monitoramento com amplo acesso à infraestrutura. Com 9 CVEs críticas no total e 3 surgidas nos últimos 90 dias, equipes que operam Zabbix em ambientes expostos devem priorizar a aplicação de patches recentes e monitorar ativamente CVE-2024-42327.

CVEs

81 resultados
CVE-2024-36464LOWMedia Types: Office365, SMTP passwords are unencrypted and visible in plaintext when exportedEPSS 0.6%CVE-2024-36468LOWStack buffer overflow in zbx_snmp_cache_handle_engineidEPSS 0.5%CVE-2024-22117LOWValue of sysmap_element_url can be de-synchronized causing the map element to crash when new URLs is addedEPSS 0.5%CVE-2025-27231MEDIUMLDAP 'Bind password' field value can be leaked by a Zabbix Super AdminEPSS 0.5%CVE-2025-27236LOWUser information disclosure via api_jsonrpc.php on method user.get with param searchEPSS 0.4%CVE-2026-23930MEDIUMFrontend DoS via the popup.testtriggerexpr actionEPSS 0.4%CVE-2024-45699HIGHReflected XSS vulnerability in /zabbix.php?action=export.valuemapsEPSS 0.4%CVE-2024-45700MEDIUMDoS vulnerability due to uncontrolled resource exhaustionEPSS 0.3%CVE-2025-49643MEDIUMFrontend DoS vulnerability due to asymmetric resource consumptionEPSS 0.3%CVE-2025-27237HIGHDLL injection in Zabbix Agent and Agent 2 via OpenSSL configurationEPSS 0.3%CVE-2024-36469LOWUser enumeration via timing attack in Zabbix web interfaceEPSS 0.3%CVE-2026-23937MEDIUMHost PSK extraction in Zabbix APIEPSS 0.3%CVE-2025-27234HIGHZabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0.EPSS 0.3%CVE-2026-23938LOWServer DoS via JavaScript preprocessing or script itemsEPSS 0.3%CVE-2026-23920HIGHHost and event action script regex validation can be bypassed in certain situations, leading to potential command injectionEPSS 0.3%CVE-2024-42325LOWExcessive information returned by user.getEPSS 0.3%CVE-2025-49641MEDIUMInsufficient permission check for the problem.view.refresh actionEPSS 0.3%CVE-2025-27232MEDIUMFrontend arbitrary file read in oauth.authorize actionEPSS 0.3%CVE-2026-23931MEDIUMFrontend plaintext macro value enumeration via the validatate.api.exists actionEPSS 0.3%CVE-2026-23922LOWEmail media OAuth secret leak to Super AdminEPSS 0.3%