Vulnerabilidades em Zabbix

83 resultados
Análise Vexday

O Zabbix apresenta uma taxa de exploração ativa 5,4 vezes acima da média geral do catálogo CISA KEV, o que indica risco operacional elevado em relação ao volume total de CVEs catalogadas. O pior caso ativo, CVE-2022-23131, registra EPSS de 0,9568 — valor que sinaliza altíssima probabilidade de exploração observada na prática — e deve ser tratado como prioridade imediata de remediação. Das 83 CVEs catalogadas, 10 são de severidade crítica e 5 possuem PoC pública disponível, ampliando a superfície de exposição para atores com capacidade técnica limitada. A falha mais recorrente (CWE-20, validação inadequada de entrada) e o surgimento de 3 novas CVEs nos últimos 90 dias reforçam a necessidade de monitoramento contínuo e ciclos curtos de atualização para ambientes que operam esta plataforma.

CVE-2022-23131CRITICALUnsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAMLEPSS 95.7%KEVCVE-2022-23134LOWPossible view of the setup pages by unauthenticated users if config file already existsEPSS 84.7%KEVCVE-2024-42327CRITICALSQL injection in user.get APIEPSS 78.8%CVE-2024-22120CRITICALTime Based SQL Injection in Zabbix Server Audit LogEPSS 76.6%CVE-2013-3628Zabbix 2.0.9 has an Arbitrary Command Execution VulnerabilityEPSS 67.5%CVE-2023-29452MEDIUMRemove possibility to add html into Geomap attribution fieldEPSS 64.1%CVE-2022-46768MEDIUMFile name information disclosure vulnerability in Zabbix Web Service Report GenerationEPSS 47.8%CVE-2024-36465HIGHSQL injection in Zabbix APIEPSS 26.5%CVE-2017-2824An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of pEPSS 25.7%CVE-2024-22122LOWAT(GSM) Command InjectionEPSS 1.6%CVE-2024-22116CRITICALRemote code execution within ping scriptEPSS 1.6%CVE-2023-29450HIGHUnauthorized limited filesystem access from preprocessingEPSS 1.3%CVE-2022-24919LOWReflected XSS in graph configuration window of Zabbix FrontendEPSS 1.2%CVE-2022-24349MEDIUMReflected XSS in action configuration window of Zabbix FrontendEPSS 1.2%CVE-2022-24917LOWReflected XSS in service configuration window of Zabbix FrontendEPSS 1.2%CVE-2022-43515MEDIUMX-Forwarded-For header is active by default causes access to Zabbix sites in maintenance modeEPSS 1.2%CVE-2025-27240HIGHSecondary-order SQL injection in Zabbix Server when deleting an autoregistered hostEPSS 1.2%CVE-2022-24918LOWReflected XSS in item configuration window of Zabbix FrontendEPSS 1.2%CVE-2023-29449MEDIUMLimited control of resource utilization in JS preprocessingEPSS 1.2%CVE-2022-23133MEDIUMStored XSS in host groups configuration window in Zabbix FrontendEPSS 1.0%