Zabbix

Zabbix

127 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 18.08.2026 12:18:53
  • Zuletzt bearbeitet 23.09.2026 14:30:27

An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.

  • EPSS 0.2%
  • Veröffentlicht 18.08.2026 12:18:09
  • Zuletzt bearbeitet 23.09.2026 14:31:46

In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In su...

  • EPSS 0.28%
  • Veröffentlicht 18.08.2026 12:17:38
  • Zuletzt bearbeitet 23.09.2026 14:38:36

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.

  • EPSS 0.17%
  • Veröffentlicht 18.08.2026 12:17:01
  • Zuletzt bearbeitet 08.09.2026 15:05:57

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

  • EPSS 0.3%
  • Veröffentlicht 18.08.2026 12:16:15
  • Zuletzt bearbeitet 08.09.2026 15:10:20

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prot...

  • EPSS 0.24%
  • Veröffentlicht 18.08.2026 12:15:29
  • Zuletzt bearbeitet 08.09.2026 15:25:05

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.

  • EPSS 0.28%
  • Veröffentlicht 18.08.2026 12:13:38
  • Zuletzt bearbeitet 08.09.2026 15:18:34

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.

  • EPSS 0.29%
  • Veröffentlicht 06.05.2026 08:16:03
  • Zuletzt bearbeitet 18.09.2026 15:19:05

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard conta...

  • EPSS 0.23%
  • Veröffentlicht 06.05.2026 08:16:02
  • Zuletzt bearbeitet 18.09.2026 15:26:56

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named sessio...

  • EPSS 0.29%
  • Veröffentlicht 06.05.2026 08:16:01
  • Zuletzt bearbeitet 18.09.2026 15:35:11

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unau...