Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Zabbix — Vulnerabilities & Security Advisories 81

All 81 CVE vulnerabilities found in Zabbix, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the Zabbix network monitoring and management platform, specifically focusing on known weaknesses affecting its server, proxy, or agent components. It collects documented defects such as memory corruption, authentication flaws, and configuration errors, covering the historical range of advisories from the product's initial release through current versions. Readers can use this resource to track the vendor's security advisories, understand the broader weakness class patterns, and look up the complete vulnerability history for Zabbix. The aggregation highlights recurring themes in security patches, enabling security teams to identify systemic risks and prioritize remediation efforts based on historical trends. By reviewing these entries, administrators can correlate specific product versions with their associated security flaws, facilitating more informed upgrade and patch management decisions without needing to search individual vendor bulletins separately.

Vendor: Zabbix

CVE ID Title CVSS Severity Published
CVE-2023-32728 Code injection in zabbix_agent2 smart.disk.get caused by smartctl plugin CWE-20 4.6 Medium 2023-12-18
CVE-2023-32727 Code execution vulnerability in icmpping CWE-20 6.8 Medium 2023-12-18
CVE-2023-32726 Possible buffer overread from reading DNS responses CWE-754 3.9 Low 2023-12-18
CVE-2023-32725 Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget. CWE-565 9.6 Critical 2023-12-18
CVE-2023-32724 JavaScript engine memory pointers are directly available for Zabbix users for modification CWE-732 9.1 Critical 2023-10-12
CVE-2023-32723 Inefficient permission check in class CControllerAuthenticationUpdate CWE-732 8.5 High 2023-10-12
CVE-2023-32722 Stack-buffer Overflow in library module zbxjson CWE-120 9.6 Critical 2023-10-12
CVE-2023-32721 Stored XSS in Maps element CWE-20 7.6 High 2023-10-12
CVE-2023-29453 Agent 2 package are built with Go version affected by CVE-2023-24538 CWE-94 9.8 Critical 2023-10-12
CVE-2023-29457 Insufficient validation of Action form input fields CWE-20 6.3 Medium 2023-07-13
CVE-2023-29458 Duktape 2.6 bug crashes JavaScript putting too many values in valstack. CWE-129 5.9 Medium 2023-07-13
CVE-2023-29456 Inefficient URL schema validation CWE-20 5.7 Medium 2023-07-13
CVE-2023-29455 Reflected XSS in several fields of graph form CWE-20 5.4 Medium 2023-07-13
CVE-2023-29454 Persistent XSS in the user form CWE-20 5.4 Medium 2023-07-13
CVE-2023-29452 Remove possibility to add html into Geomap attribution field CWE-20 5.5 Medium 2023-07-13
CVE-2023-29451 Denial of service caused by a bug in the JSON parser CWE-20 4.7 Medium 2023-07-13
CVE-2023-29450 Unauthorized limited filesystem access from preprocessing CWE-200 8.5 High 2023-07-13
CVE-2023-29449 Limited control of resource utilization in JS preprocessing CWE-400 5.9 Medium 2023-07-13
CVE-2013-3628 Zabbix 注入漏洞 8.8 - 2020-02-07
CVE-2017-2825 Zabbix Server 安全漏洞 7.0 - 2018-04-20
CVE-2017-2826 Zabbix Server 信息泄露漏洞 7.5 - 2018-04-09

All 81 known CVE vulnerabilities affecting Zabbix with full Chinese analysis, references, and POCs where available.