VYPR

Vendor CVEs

Checkmk

All CVEs

127 total · sorted by risk
  • CVE-2026-3466MedApr 7, 2026
    risk 0.28cvss 5.4epss 0.00

    Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0 allows an attacker with dashboard creation privileges to perform stored cross-site scripting…

  • CVE-2026-33276MedMar 31, 2026
    risk 0.28cvss 5.4epss 0.00

    Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Unified Search feature.

  • CVE-2026-20915MedMar 31, 2026
    risk 0.28cvss 5.4epss 0.00

    Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in the browsers of other users viewing the…

  • CVE-2026-24097MedMar 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to…

  • CVE-2025-32916MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various places such as browser history or web…

  • CVE-2024-38857MedJul 2, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attackers to craft malicious links that can facilitate phishing attacks.

  • CVE-2023-22359MedJun 26, 2023
    risk 0.28cvss 4.3epss 0.01

    User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.

  • CVE-2023-22348MedMay 17, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.

  • CVE-2023-2020MedApr 18, 2023
    risk 0.28cvss 4.3epss 0.00

    Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.

  • CVE-2026-7765MedJun 8, 2026
    risk 0.27cvss 5.3epss 0.00

    Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's…

  • CVE-2023-22288MedMar 20, 2023
    risk 0.27cvss 4.1epss 0.00

    HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails

  • CVE-2024-1742LowMar 22, 2024
    risk 0.25cvss 3.8epss 0.00

    Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list.

  • CVE-2026-9549MedJun 8, 2026
    risk 0.24cvss 4.8epss 0.00

    Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in…

  • CVE-2026-8078MedJun 8, 2026
    risk 0.24cvss 4.8epss 0.00

    Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users'…

  • CVE-2023-1768LowApr 4, 2023
    risk 0.24cvss 3.7epss 0.01

    Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.

  • CVE-2023-6251LowNov 24, 2023
    risk 0.23cvss 3.5epss 0.00

    Cross-site Request Forgery (CSRF) in Checkmk < 2.2.0p15, < 2.1.0p37, <= 2.0.0p39 allow an authenticated attacker to delete user-messages for individual users.

  • CVE-2022-4884LowJan 9, 2023
    risk 0.23cvss 3.5epss 0.00

    Path-Traversal in MKP storing in Tribe29 Checkmk <=2.0.0p32 and <= 2.1.0p18 allows an administrator to write mkp files to arbitrary locations via a malicious mkp file.

  • CVE-2026-2859MedMar 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deploy_agent endpoint, which could lead to information…

  • CVE-2023-6287LowNov 27, 2023
    risk 0.21cvss 3.3epss 0.00

    Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.

  • CVE-2024-28830LowJun 26, 2024
    risk 0.18cvss 2.7epss 0.00

    Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <=2.0.0p39 (EOL) causes automation user secrets to be written to audit log files accessible to administrators.

  • CVE-2023-23549LowNov 15, 2023
    risk 0.18cvss 2.7epss 0.01

    Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial denial of service of the UI via too long hostnames.

  • CVE-2024-38864LowDec 19, 2024
    risk 0.14cvss 3.3epss 0.00

    Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.

  • CVE-2026-15227MedJul 31, 2026
    risk 0.00cvss epss 0.00

    Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

  • CVE-2026-8593MedJul 21, 2026
    risk 0.00cvss epss 0.00

    Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules

  • CVE-2026-14852MedJul 14, 2026
    risk 0.00cvss epss 0.00

    Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary commands as root by starting a process crafted to look like a SAP HANA instance. Without an explicit…

  • CVE-2024-47092CriMar 3, 2025
    risk 0.00cvss 9.8epss 0.00

    Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1

  • CVE-2020-28919MedJan 15, 2022
    risk 0.00cvss 5.4epss 0.01

    A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.

Page 3 of 3