Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zabbix

First CVE: Dec 21, 2006Active for: 20 yearsTotal CVEs: 128
64.9
VTI Score
TOP TARGET

Zabbix maintains a focused monitoring and observability platform that, despite a narrow product portfolio, is widely deployed across enterprise infrastructure and cloud environments, concentrating significant attack surface in its server, frontend, and agent components. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability, reflecting the centrality of monitoring systems to network visibility and the web-facing nature of its management interface. The exposure recurs through web-application and input-handling weakness classes, including cross-site scripting, SQL injection, improper input validation, and code injection, which are characteristic of monitoring platforms that must parse diverse data sources and present them through dynamic dashboards. Defenders should treat Zabbix vulnerabilities as high-priority for internet-reachable instances and API endpoints, since successful exploitation can grant attackers extensive visibility into monitored infrastructure. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
128
Total CVEs
More Total CVEs than 99% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
1.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Zabbix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 21, 2006
19 years ago
Most Recent CVE
May 6, 2026
79 days ago

Self-Reporting Analysis

Of all the CVEs published by Zabbix as a CNA, 100.0% affect products that Zabbix develops as a vendor.

100.0%
Self-reported: 81 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by Zabbix, 63.3% are self-published by Zabbix as a CNA.

63.3%
36.7%
Self-published: 81 (63.3%)
Other CNAs: 47 (36.7%)

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (128 CVEs).

128 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-23131CRITICAL
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session w
Jan 13, 20229.897YESYES
CVE-2022-23134MEDIUM
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step ch
Jan 13, 20225.394YESYES
CVE-2013-5743CRITICAL
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
Dec 11, 20199.887NOYES
CVE-2016-10134CRITICAL
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
Feb 17, 20179.886NOYES
CVE-2024-42327CRITICAL
A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser
Nov 27, 20249.984NOYES
CVE-2024-22120HIGH
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is
May 17, 20248.880NOYES
CVE-2013-3628HIGH
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
Feb 7, 20208.876NOYES
CVE-2019-17382CRITICAL
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then creat
Oct 9, 20199.169NOYES
CVE-2009-4498MEDIUM
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.
Dec 31, 20096.855NOYES
CVE-2009-4502HIGH
The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execut
Dec 31, 20099.352NOYES
View all 128 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products128 CVEs
10%
41%
36%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (6.3%)
Network85 (66.4%)
Unknown28 (21.9%)
Physical0 (0.0%)
Adjacent Network4 (3.1%)
Attack Complexity
Low86 (67.2%)
High14 (10.9%)
Unknown28 (21.9%)
User Interaction
None76 (59.4%)
Unknown28 (21.9%)
Required22 (17.2%)
Privileges Required
Low39 (30.5%)
High20 (15.6%)
None41 (32.0%)
Unknown28 (21.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (128 CVEs).

CISA KEV
2 CVEs
1.6% of CVEs· 99th percentile
Metasploit
5 CVEs
3.9% of CVEs· 98th percentile
Nuclei
5 CVEs
3.9% of CVEs· 95th percentile
ExploitDB
14 CVEs
10.9% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zabbix.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zabbix — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zabbix's Products

View all 7 CNAs →

Top CWEs