Zabbix

Zabbix

127 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 03.10.2025 11:28:43
  • Zuletzt bearbeitet 15.04.2026 00:35:42

In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.

  • EPSS 0.35%
  • Veröffentlicht 03.10.2025 11:28:09
  • Zuletzt bearbeitet 08.10.2025 14:54:42

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.

  • EPSS 0.39%
  • Veröffentlicht 03.10.2025 11:25:14
  • Zuletzt bearbeitet 08.10.2025 14:54:17

The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind password' value is now reset on 'Host' change.

  • EPSS 1.27%
  • Veröffentlicht 12.09.2025 10:33:46
  • Zuletzt bearbeitet 08.10.2025 14:53:38

A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.

  • EPSS 0.18%
  • Veröffentlicht 12.09.2025 10:33:17
  • Zuletzt bearbeitet 08.10.2025 14:53:00

Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.

  • EPSS 0.17%
  • Veröffentlicht 12.09.2025 10:32:36
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.

  • EPSS 0.31%
  • Veröffentlicht 12.09.2025 10:31:58
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.

Medienbericht
  • EPSS 0.29%
  • Veröffentlicht 02.04.2025 07:15:41
  • Zuletzt bearbeitet 03.11.2025 20:16:28

Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.

Medienbericht
  • EPSS 0.35%
  • Veröffentlicht 02.04.2025 07:15:41
  • Zuletzt bearbeitet 03.11.2025 20:16:30

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a ...

Medienbericht
  • EPSS 0.35%
  • Veröffentlicht 02.04.2025 07:15:41
  • Zuletzt bearbeitet 03.11.2025 20:16:31

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive...