Zabbix maintains a focused monitoring and observability platform that, despite a narrow product portfolio, is widely deployed across enterprise infrastructure and cloud environments, concentrating significant attack surface in its server, frontend, and agent components. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability, reflecting the centrality of monitoring systems to network visibility and the web-facing nature of its management interface. The exposure recurs through web-application and input-handling weakness classes, including cross-site scripting, SQL injection, improper input validation, and code injection, which are characteristic of monitoring platforms that must parse diverse data sources and present them through dynamic dashboards. Defenders should treat Zabbix vulnerabilities as high-priority for internet-reachable instances and API endpoints, since successful exploitation can grant attackers extensive visibility into monitored infrastructure. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zabbix over time
Of all the CVEs published by Zabbix as a CNA, 100.0% affect products that Zabbix develops as a vendor.
Of all the CVEs published that affect products developed by Zabbix, 63.3% are self-published by Zabbix as a CNA.
Signals from CVEs in this vendor scope (128 CVEs).
128 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23131CRITICAL In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session w | Jan 13, 2022 | 9.8 | 97 | YES | YES |
CVE-2022-23134MEDIUM After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step ch | Jan 13, 2022 | 5.3 | 94 | YES | YES |
CVE-2013-5743CRITICAL Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7. | Dec 11, 2019 | 9.8 | 87 | NO | YES |
CVE-2016-10134CRITICAL SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php. | Feb 17, 2017 | 9.8 | 86 | NO | YES |
CVE-2024-42327CRITICAL A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser | Nov 27, 2024 | 9.9 | 84 | NO | YES |
CVE-2024-22120HIGH Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is | May 17, 2024 | 8.8 | 80 | NO | YES |
CVE-2013-3628HIGH Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability | Feb 7, 2020 | 8.8 | 76 | NO | YES |
CVE-2019-17382CRITICAL An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then creat | Oct 9, 2019 | 9.1 | 69 | NO | YES |
CVE-2009-4498MEDIUM The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request. | Dec 31, 2009 | 6.8 | 55 | NO | YES |
CVE-2009-4502HIGH The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execut | Dec 31, 2009 | 9.3 | 52 | NO | YES |
Signals from CVEs in this vendor scope (128 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zabbix.
Media articles that mention a CVE ID that affects a product developed by Zabbix — matched by CVE ID, not by vendor name.