vendor

zabbix

17 thingsrelated by NVD

Its products

zabbix 15 frontend 2

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected…
CVE-2026-59781
Severity high
zabbix: Zabbix: Denial of Service via crafted JavaScript scripts
CVE-2026-23938
Severity medium
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data…
CVE-2026-23937
Severity medium
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest…
CVE-2026-23935
Severity medium
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the…
CVE-2026-23934
Severity medium
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the…
CVE-2026-23933
Severity critical
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to…
CVE-2026-23931
Severity medium
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is…
CVE-2026-23928
Severity medium
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2…
CVE-2026-23927
Severity medium
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that…
CVE-2026-23926
Severity medium
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon…
CVE-2026-23924
Severity medium
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on…
CVE-2026-23923
Severity medium
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to…
CVE-2026-23921
Severity high
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^…
CVE-2026-23920
Severity high
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)…
CVE-2026-23919
Severity medium
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted…
CVE-2025-49643
Severity medium
zabbix: Zabbix: Authenticated Super Admin can read arbitrary files via oauth.authorize action
CVE-2025-27232
Severity medium