Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Zabbix — Vulnerabilities & Security Advisories 70

All 70 CVE vulnerabilities found in Zabbix, with AI-generated Chinese analysis, references, and POCs.

This page presents a comprehensive aggregation of Common Weakness Enumerations (CWE) associated with Zabbix, developed by Zabbix SIA. It compiles historical security data regarding known vulnerabilities, design flaws, and implementation errors that have impacted the Zabbix monitoring platform over time. The content covers security incidents and advisory records dating back to the early releases of the software, providing a long-term view of its security posture. Readers can utilize this resource to track vendor advisories issued by Zabbix SIA, understand specific weakness classes such as cross-site scripting or insecure default configurations, and look up the product's vulnerability history to assess risk trends. This collection serves as a factual reference for security researchers, system administrators, and penetration testers seeking to audit the Zabbix environment or study the evolution of defects in enterprise monitoring tools. The data is organized to facilitate the identification of recurring issues and the verification of patch statuses without relying on marketing narratives. By aggregating these records, the page offers a neutral, structured overview of security incidents, enabling stakeholders to make informed decisions regarding system hardening, upgrade paths, and third-party component assessments within their deployment architectures.

Vendor: Zabbix

CVE IDTitleCVSSSeverityPublished
CVE-2024-42330 JS - Internal strings in HTTP headers CWE-134 9.1 Critical2024-11-27
CVE-2024-42329 JS - Crash on unexpected HTTP server response CWE-690 3.3 Low2024-11-27
CVE-2024-42328 JS - Crash on empty HTTP server response CWE-690 3.3 Low2024-11-27
CVE-2024-42327 SQL injection in user.get API CWE-89 9.9 Critical2024-11-27
CVE-2024-42326 Use after free vulnerability in browser.c CWE-416 4.4 Medium2024-11-27
CVE-2024-36468 Stack buffer overflow in zbx_snmp_cache_handle_engineid CWE-121 3.0 Low2024-11-27
CVE-2024-36467 Authentication privilege escalation via user groups due to missing authorization checks CWE-285 7.5 High2024-11-27
CVE-2024-36463 Zabbix 安全漏洞 CWE-767 6.5 Medium2024-11-26
CVE-2024-22117 Value of sysmap_element_url can be de-synchronized causing the map element to crash when new URLs is added CWE-20 2.2 Low2024-11-26
CVE-2024-22123 Zabbix Arbitrary File Read CWE-94 2.7 Low2024-08-09
CVE-2024-22116 Remote code execution within ping script CWE-94 9.9 Critical2024-08-09
CVE-2024-22114 System Information Widget in Global View Dashboard exposes information about Hosts to Users without Permission CWE-281 4.3 Medium2024-08-09
CVE-2024-36462 Allocation of resources without limits or throttling (uncontrolled resource consumption) CWE-770 7.5 High2024-08-09
CVE-2024-36461 Direct access to memory pointers within the JS engine for modification CWE-822 9.1 Critical2024-08-09
CVE-2024-36460 Front-end audit log shows passwords in plaintext CWE-256 8.1 High2024-08-09
CVE-2024-22122 AT(GSM) Command Injection CWE-77 3.0 Low2024-08-09
CVE-2024-22121 Zabbix Agent MSI Installer Allows Non-Admin User to Access Change Option via msiexec.exe CWE-281 6.1 Medium2024-08-09
CVE-2024-22120 Time Based SQL Injection in Zabbix Server Audit Log CWE-20 9.1 Critical2024-05-17
CVE-2024-22119 Stored XSS in graph items select form CWE-20 5.5 Medium2024-02-09
CVE-2023-32728 Code injection in zabbix_agent2 smart.disk.get caused by smartctl plugin CWE-20 4.6 Medium2023-12-18
CVE-2023-32727 Code execution vulnerability in icmpping CWE-20 6.8 Medium2023-12-18
CVE-2023-32726 Possible buffer overread from reading DNS responses CWE-754 3.9 Low2023-12-18
CVE-2023-32725 Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget. CWE-565 9.6 Critical2023-12-18
CVE-2023-32724 JavaScript engine memory pointers are directly available for Zabbix users for modification CWE-732 9.1 Critical2023-10-12
CVE-2023-32723 Inefficient permission check in class CControllerAuthenticationUpdate CWE-732 8.5 High2023-10-12
CVE-2023-32722 Stack-buffer Overflow in library module zbxjson CWE-120 9.6 Critical2023-10-12
CVE-2023-32721 Stored XSS in Maps element CWE-20 7.6 High2023-10-12
CVE-2023-29453 Agent 2 package are built with Go version affected by CVE-2023-24538 CWE-94 9.8 Critical2023-10-12
CVE-2023-29457 Insufficient validation of Action form input fields CWE-20 6.3 Medium2023-07-13
CVE-2023-29458 Duktape 2.6 bug crashes JavaScript putting too many values in valstack. CWE-129 5.9 Medium2023-07-13

All 70 known CVE vulnerabilities affecting Zabbix with full Chinese analysis, references, and POCs where available.