Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Zabbix — Vulnerabilities & Security Advisories 81

All 81 CVE vulnerabilities found in Zabbix, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the Zabbix network monitoring and management platform, specifically focusing on known weaknesses affecting its server, proxy, or agent components. It collects documented defects such as memory corruption, authentication flaws, and configuration errors, covering the historical range of advisories from the product's initial release through current versions. Readers can use this resource to track the vendor's security advisories, understand the broader weakness class patterns, and look up the complete vulnerability history for Zabbix. The aggregation highlights recurring themes in security patches, enabling security teams to identify systemic risks and prioritize remediation efforts based on historical trends. By reviewing these entries, administrators can correlate specific product versions with their associated security flaws, facilitating more informed upgrade and patch management decisions without needing to search individual vendor bulletins separately.

Vendor: Zabbix

CVE ID Title CVSS Severity Published
CVE-2025-27234 Zabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0. CWE-78 9.8 - 2025-09-12
CVE-2024-45700 DoS vulnerability due to uncontrolled resource exhaustion CWE-770 7.5AI High AI 2025-04-02
CVE-2024-45699 Reflected XSS vulnerability in /zabbix.php?action=export.valuemaps CWE-79 6.1AI Medium AI 2025-04-02
CVE-2024-42325 Excessive information returned by user.get CWE-359 7.5AI High AI 2025-04-02
CVE-2024-36469 User enumeration via timing attack in Zabbix web interface CWE-208 9.4AI Critical AI 2025-04-02
CVE-2024-36465 SQL injection in Zabbix API CWE-89 8.8AI High AI 2025-04-02
CVE-2024-36466 Unauthenticated Zabbix frontend takeover when SSO is being used CWE-290 8.8 High 2024-11-28
CVE-2024-36464 Media Types: Office365, SMTP passwords are unencrypted and visible in plaintext when exported CWE-256 2.7 Low 2024-11-27
CVE-2024-42333 Heap buffer over-read CWE-126 2.7 Low 2024-11-27
CVE-2024-42332 New line injection in Zabbix SNMP traps 3.7 Low 2024-11-27
CVE-2024-42331 Use after free in browser_push_error CWE-416 3.3 Low 2024-11-27
CVE-2024-42330 JS - Internal strings in HTTP headers CWE-134 9.1 Critical 2024-11-27
CVE-2024-42329 JS - Crash on unexpected HTTP server response CWE-690 3.3 Low 2024-11-27
CVE-2024-42328 JS - Crash on empty HTTP server response CWE-690 3.3 Low 2024-11-27
CVE-2024-42327 SQL injection in user.get API CWE-89 9.9 Critical 2024-11-27
CVE-2024-42326 Use after free vulnerability in browser.c CWE-416 4.4 Medium 2024-11-27
CVE-2024-36468 Stack buffer overflow in zbx_snmp_cache_handle_engineid CWE-121 3.0 Low 2024-11-27
CVE-2024-36467 Authentication privilege escalation via user groups due to missing authorization checks CWE-285 7.5 High 2024-11-27
CVE-2024-36463 Zabbix 安全漏洞 CWE-767 6.5 Medium 2024-11-26
CVE-2024-22117 Value of sysmap_element_url can be de-synchronized causing the map element to crash when new URLs is added CWE-20 2.2 Low 2024-11-26
CVE-2024-22123 Zabbix Arbitrary File Read CWE-94 2.7 Low 2024-08-09
CVE-2024-22116 Remote code execution within ping script CWE-94 9.9 Critical 2024-08-09
CVE-2024-22114 System Information Widget in Global View Dashboard exposes information about Hosts to Users without Permission CWE-281 4.3 Medium 2024-08-09
CVE-2024-36462 Allocation of resources without limits or throttling (uncontrolled resource consumption) CWE-770 7.5 High 2024-08-09
CVE-2024-36461 Direct access to memory pointers within the JS engine for modification CWE-822 9.1 Critical 2024-08-09
CVE-2024-36460 Front-end audit log shows passwords in plaintext CWE-256 8.1 High 2024-08-09
CVE-2024-22122 AT(GSM) Command Injection CWE-77 3.0 Low 2024-08-09
CVE-2024-22121 Zabbix Agent MSI Installer Allows Non-Admin User to Access Change Option via msiexec.exe CWE-281 6.1 Medium 2024-08-09
CVE-2024-22120 Time Based SQL Injection in Zabbix Server Audit Log CWE-20 9.1 Critical 2024-05-17
CVE-2024-22119 Stored XSS in graph items select form CWE-20 5.5 Medium 2024-02-09

All 81 known CVE vulnerabilities affecting Zabbix with full Chinese analysis, references, and POCs where available.