Where
-Infinity
0

Zabbix ZabbixStored XSS vulnerability in the Item history/Plain text widget

Risk 62
Severity
7.3
First published (updated )

Zabbix Zabbix Agent 2 Docker pluginAgent 2 Docker plugin arbitrary file read via Docker API injection

Risk 36
Severity
6.1
First published (updated )

Zabbix ZabbixBlind, read-only SQL injection in Zabbix API via sortfield parameter

Risk 79
Severity
8.7
First published (updated )

Zabbix Zabbix serverInsufficient isolation of JavaScript (Duktape) execution context on Zabbix Server

Risk 48
Severity
7.1
First published (updated )

Zabbix ZabbixUnauthorized host creation via configuration.import API by low-privilege user with write permissions

Risk 60
Severity
5.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zabbix FrontendFrontend DoS vulnerability due to asymmetric resource consumption

Risk 38
Severity
6.5
First published (updated )

Zabbix ZabbixFrontend arbitrary file read in oauth.authorize action

Risk 35
Severity
6.8
First published (updated )

Zabbix ZabbixInsufficient permission check for the problem.view.refresh action

Risk 24
Severity
5.1
First published (updated )

Zabbix Zabbix AgentDLL injection in Zabbix Agent and Agent 2 via OpenSSL configuration

Risk 66
Severity
7.3
First published (updated )

Zabbix ZabbixUser information disclosure via api_jsonrpc.php on method user.get with param search

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zabbix ZabbixLDAP 'Bind password' field value can be leaked by a Zabbix Super Admin

Risk 30
Severity
4.9
First published (updated )

Zabbix ZabbixSecondary-order SQL injection in Zabbix Server when deleting an autoregistered host

Risk 66
Severity
7.5
First published (updated )

Zabbix ZabbixAPI hostprototype.get lists data to users with insufficient authorization.

Risk 19
Severity
3.5
First published (updated )

Zabbix Zabbix Agent 2Zabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later.

Risk 29
Severity
5.7
First published (updated )

Zabbix ZabbixZabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0.

Risk 63
Severity
7.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zabbix ZabbixDoS vulnerability due to uncontrolled resource exhaustion

Risk 38
Severity
6.5
First published (updated )

Zabbix ZabbixReflected XSS vulnerability in /zabbix.php?action=export.valuemaps

Risk 73
Severity
7.5
First published (updated )

Zabbix ZabbixExcessive information returned by user.get

Risk 19
Severity
3.5
First published (updated )

Zabbix ZabbixUser enumeration via timing attack in Zabbix web interface

Risk 17
Severity
3.1
First published (updated )

Zabbix ZabbixSQL injection in Zabbix API

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zabbix ZabbixUnauthenticated Zabbix frontend takeover when SSO is being used

Risk 79
Severity
8.8
First published (updated )

Zabbix ZabbixMedia Types: Office365, SMTP passwords are unencrypted and visible in plaintext when exported

Risk 16
Severity
2.7
First published (updated )

Zabbix ZabbixHeap buffer over-read

Risk 16
Severity
2.7
First published (updated )

Zabbix ZabbixNew line injection in Zabbix SNMP traps

Risk 20
Severity
3.7
First published (updated )

Zabbix ZabbixUse after free in browser_push_error

Risk 18
Severity
3.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zabbix ZabbixJS - Internal strings in HTTP headers

Risk 72
Severity
9.1
First published (updated )

Zabbix ZabbixJS - Crash on unexpected HTTP server response

Risk 18
Severity
3.3
First published (updated )

Zabbix ZabbixJS - Crash on empty HTTP server response

Risk 32
Severity
5.5
First published (updated )

Zabbix ZabbixSQL injection in user.get API

Risk 100
Severity
9.9
First published (updated )

Zabbix ZabbixUse after free vulnerability in browser.c

Risk 29
Severity
4.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203