VYPR

Checkmk

by Checkmk

Source repositories

CVEs (116)

  • CVE-2023-0284MedJan 26, 2023
    risk 0.44cvss 6.8epss 0.01

    Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.

  • CVE-2026-33456HigApr 10, 2026
    risk 0.42cvss 7.6epss 0.00

    Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description.

  • CVE-2025-64997MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view agent information via the REST API, which could lead to information disclosure.

  • CVE-2024-6542MedJul 22, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.

  • CVE-2024-6052MedJul 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements

  • CVE-2024-5741MedJun 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)

  • CVE-2024-3367MedApr 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmqsc

  • CVE-2022-48319MedFeb 20, 2023
    risk 0.42cvss 6.5epss 0.00

    Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.

  • CVE-2017-14955MedOct 2, 2017
    risk 0.42cvss 5.9epss 0.12

    Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

  • CVE-2025-39666HigApr 7, 2026
    risk 0.40cvss 7.3epss 0.00

    Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site context that are processed when the…

  • CVE-2025-64998HigMar 24, 2026
    risk 0.40cvss 7.2epss 0.00

    Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.

  • CVE-2024-38860MedSep 17, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.

  • CVE-2024-38859MedAug 26, 2024
    risk 0.40cvss 6.1epss 0.00

    XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view…

  • CVE-2023-22309MedApr 20, 2023
    risk 0.40cvss 6.1epss 0.00

    Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.

  • CVE-2021-40906MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as…

  • CVE-2022-24564MedFeb 21, 2022
    risk 0.40cvss 6.1epss 0.01

    Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.

  • CVE-2024-28833MedJun 10, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms.

  • CVE-2024-28825MedApr 24, 2024
    risk 0.38cvss 5.9epss 0.01

    Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitates password brute-forcing.

  • CVE-2025-32915MedMay 22, 2025
    risk 0.36cvss 5.5epss 0.00

    Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.

  • CVE-2024-47094MedNov 29, 2024
    risk 0.36cvss 5.5epss 0.00

    Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.

Page 3 of 6