Exposição de Zabbix

Miscellaneous
29
score de exposição
6
sites usam
0
em exploração
9
críticos
Análise Vexday

Com 70 CVEs catalogadas, o Zabbix apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de uso malicioso ativo no momento. No entanto, a ausência de exploração confirmada não elimina o risco: CVE-2024-42327 concentra um escore EPSS de 0,7883, indicando probabilidade elevada de exploração futura segundo modelos preditivos. O tipo de falha mais recorrente é CWE-20 (validação imprópria de entrada), padrão que historicamente facilita encadeamento de vulnerabilidades em plataformas de monitoramento com amplo acesso à infraestrutura. Com 9 CVEs críticas no total e 3 surgidas nos últimos 90 dias, equipes que operam Zabbix em ambientes expostos devem priorizar a aplicação de patches recentes e monitorar ativamente CVE-2024-42327.

CVEs

81 resultados
CVE-2026-23923MEDIUMUnauthenticated arbitrary PHP class instantiationEPSS 0.3%CVE-2026-23928HIGHStored XSS vulnerability in the Item history/Plain text widgetEPSS 0.3%CVE-2026-23926HIGHStored XSS vulnerability in Host navigator widget maintenance tooltipEPSS 0.3%CVE-2024-42331LOWUse after free in browser_push_errorEPSS 0.3%CVE-2026-23925MEDIUMUnauthorized host creation via configuration.import API by low-privilege user with write permissionsEPSS 0.3%CVE-2024-42329LOWJS - Crash on unexpected HTTP server responseEPSS 0.2%CVE-2026-23919HIGHInsufficient isolation of JavaScript (Duktape) execution context on Zabbix ServerEPSS 0.2%CVE-2024-42326MEDIUMUse after free vulnerability in browser.cEPSS 0.2%CVE-2024-42328LOWJS - Crash on empty HTTP server responseEPSS 0.2%CVE-2026-23924MEDIUMAgent 2 Docker plugin arbitrary file read via Docker API injectionEPSS 0.2%CVE-2024-22121MEDIUMZabbix Agent MSI Installer Allows Non-Admin User to Access Change Option via msiexec.exeEPSS 0.2%CVE-2026-23927MEDIUMAgent 2 Oracle plugin TNS connection string injection via the 'service' parameterEPSS 0.2%CVE-2026-23933HIGHHardcoded session key in Zabbix 7.4EPSS 0.2%CVE-2025-27238LOWAPI hostprototype.get lists data to users with insufficient authorization.EPSS 0.2%CVE-2026-23929HIGHPrototype pollution leading to stored XSSEPSS 0.2%CVE-2026-23935MEDIUMUse-after-free read in script item/preprocessing HttpRequest bodyEPSS 0.2%CVE-2025-27233MEDIUMZabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later.EPSS 0.2%CVE-2026-23934MEDIUMFrontend DoS via the validate.api.exists actionEPSS 0.2%CVE-2026-1199MEDIUMAPI and Frontend login lockout race conditionEPSS 0.2%CVE-2025-49642MEDIUMAgent builds for AIX vulnerable to library loading hijackingEPSS 0.1%