Zabbix-llc
51 CVEs tracked since 2022. Since Jan 2022, 2 of them reached CISA KEV.
Zabbix-llc CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-01 | 6 | 2 |
| 2022-02 | null or fewer | |
| 2022-03 | 4 | 0 |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | null or fewer | |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | 9 | 0 |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | 5 | 0 |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | 8 | 0 |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | 14 | 0 |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | 5 | 0 |
Products
The products that kept showing up in Zabbix-llc's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Zabbix-llc.
- CVE-2026-23928Stored XSS vulnerability in the Item history/Plain text widget6.8
- CVE-2026-23926Stored XSS vulnerability in Host navigator widget maintenance tooltip6.8
- CVE-2026-23924Agent 2 Docker plugin arbitrary file read via Docker API injection4.9
- CVE-2026-23923Unauthenticated arbitrary PHP class instantiation5.3
- CVE-2026-23921Blind, read-only SQL injection in Zabbix API via sortfield parameter8.8
- CVE-2026-23920Host and event action script regex validation can be bypassed in certain situations, leading to potential command injection8.8
- CVE-2026-23919Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server6.0
- CVE-2026-23925Unauthorized host creation via configuration.import API by low-privilege user with write permissions8.1
- CVE-2025-49643Frontend DoS vulnerability due to asymmetric resource consumption6.5
- CVE-2025-49642Agent builds for AIX vulnerable to library loading hijacking7.3
- CVE-2025-27232Frontend arbitrary file read in oauth.authorize action4.9
- CVE-2025-49641Insufficient permission check for the problem.view.refresh action4.3
- CVE-2025-27237DLL injection in Zabbix Agent and Agent 2 via OpenSSL configuration7.8
- CVE-2025-27236User information disclosure via api_jsonrpc.php on method user.get with param search6.5
- CVE-2025-27231LDAP 'Bind password' field value can be leaked by a Zabbix Super Admin4.9
The record
- Peak rank
- #77 in Nov 2024
- Busiest month shown
- Nov 2024, 14 CVEs
- Months with a KEV entry
- 1 since Jan 2022
- Monthly snapshots
- 7 since 2022