Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
–

146 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.3)0.23%—ZabbixAI5/10/20266/10/2026
The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
Pendiente de análisisMedia (6.9)0.20%—Zabbix ServerAIZabbix ProxyAI5/10/20266/10/2026
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
Pendiente de análisisBaja (2.3)0.23%—Zabbix ServerAIZabbix ProxyAI5/10/20266/10/2026
The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
Pendiente de análisisMedia (6.9)0.24%—Zabbix ServerAI5/10/20266/10/2026
The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
AplazadaAlta (8.3)0.36%—Zabbix FrontendAI13/9/202624/9/2026
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing…
AnalizadaMedia (5.3)0.40%—Zabbix18/8/20268/9/2026
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.
AnalizadaAlta (8.5)0.18%—Zabbix18/8/20268/9/2026
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.
AnalizadaBaja (2.1)0.27%—Zabbix18/8/20268/9/2026
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
AnalizadaMedia (6.9)0.17%—Zabbix18/8/20268/9/2026
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.
AnalizadaMedia (5.4)0.12%—Zabbix18/8/202623/9/2026
When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to modify its contents, an attacker could place a malicious DLL that could later be loaded by…
AnalizadaBaja (2.1)0.35%—Zabbix18/8/202623/9/2026
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
AnalizadaMedia (6)0.27%—Zabbix18/8/202623/9/2026
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
AnalizadaMedia (6.8)0.34%—Zabbix18/8/202623/9/2026
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
AnalizadaMedia (5.1)0.36%—Zabbix18/8/202623/9/2026
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.
AnalizadaAlta (7.7)0.36%—Zabbix18/8/202623/9/2026
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used to forge valid session cookies,…
AnalizadaMedia (5.3)0.23%—Zabbix18/8/202623/9/2026
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
AnalizadaAlta (7.3)0.26%—Zabbix6/5/202618/9/2026
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from…
AnalizadaMedia (5.1)0.22%—Zabbix6/5/202618/9/2026
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.
AnalizadaAlta (7.3)0.26%—Zabbix6/5/202618/9/2026
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
AnalizadaMedia (6.9)0.27%—Zabbix24/3/202610/9/2026
Un atacante no autenticado puede explotar la acción 'validate' del Frontend para instanciar ciegamente clases PHP arbitrarias. El impacto depende de la configuración del entorno pero parece limitado en este momento.
AnalizadaAlta (8.7)3.9%💥 PoCZabbix24/3/202610/9/2026
Un usuario de Zabbix con privilegios bajos y acceso a la API puede explotar una vulnerabilidad de inyección SQL ciega en include/classes/api/CApiService.php para ejecutar sentencias SELECT de SQL arbitrarias a través del parámetro sortfield. Aunque los resultados de la consulta no se devuelven directamente, un…
AnalizadaAlta (7.7)0.30%—Zabbix24/3/202610/9/2026
La entrada de scripts de acción de host y evento se valida con una expresión regular (regex) (establecida por el administrador), pero la validación se ejecuta en modo multilínea. Si los anclajes ^ y $ se utilizan en la validación de entrada del usuario, un salto de línea inyectado permite a los usuarios autenticados…
AnalizadaMedia (6.1)0.23%—Zabbix24/3/202618/9/2026
El plugin de Docker de Zabbix Agent 2 no sanitiza correctamente los parámetros 'docker.container_info' al reenviarlos al demonio de Docker. Un atacante capaz de invocar a Agent 2 puede leer archivos arbitrarios de contenedores Docker en ejecución inyectándolos a través de la API de archivo de Docker.
AnalizadaAlta (7.1)0.24%—Zabbix24/3/202618/9/2026
Por razones de rendimiento, Zabbix Server/Proxy reutiliza contextos de JavaScript (Duktape) (utilizados en elementos de script, reprocesamiento de JavaScript, Webhooks). Esto puede llevar a una pérdida de confidencialidad donde un administrador de Zabbix regular (no-super) filtra datos de hosts a los que no tiene…
AnalizadaMedia (5.1)0.26%—Zabbix6/3/202617/6/2026
Un usuario autenticado de Zabbix (rol de usuario) con permisos de escritura de plantillas/hosts puede crear objetos a través de la API configuration.import. Esto puede llevar a una pérdida de confidencialidad al crear hosts no autorizados. Tenga en cuenta que el rol de usuario normalmente no es suficiente para crear y…
Orbitaley — Vulnerabilidades