Vulnerability index

Browse CVEs

47 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Checkmk HIGH 7.5
CVE-2024-28833

Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forc…

Mitigation only
Fix from $1,950 2024-06-10
Checkmk MEDIUM 5.4
CVE-2024-2380

Stored XSS in graph rendering in Checkmk <2.3.0b4.

Mitigation only
Fix from $1,600 2024-04-05
Checkmk HIGH 7.8
CVE-2023-31210

Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via inject…

Mitigation only
Fix from $1,950 2023-12-13
Checkmk HIGH 8.8
CVE-2023-6156

Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbit…

Mitigation only
Fix from $1,950 2023-11-22
Checkmk HIGH 8.8
CVE-2023-6157

Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatu…

Mitigation only
Fix from $1,950 2023-11-22
Checkmk MEDIUM 5.5
CVE-2023-31207

Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret…

Mitigation only
Fix from $1,600 2023-05-02
Checkmk HIGH 8.8
CVE-2022-46302

Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations…

Mitigation only
Fix from $1,950 2023-04-20
Checkmk CRITICAL 9.8
CVE-2022-48317

Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use ex…

Mitigation only
Fix from $2,300 2023-02-20
Checkmk HIGH 8.8
CVE-2022-46836

PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an atta…

No fix yet
Fix from $1,950 2023-02-20
Checkmk HIGH 7.8
CVE-2022-47909

Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions o…

No fix yet
Fix from $1,950 2023-02-20
Checkmk HIGH 7.5
CVE-2022-46303

Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Mana…

Mitigation only
Fix from $1,950 2023-02-20
Checkmk MEDIUM 5.5
CVE-2022-48319

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0…

Mitigation only
Fix from $1,600 2023-02-20
Checkmk MEDIUM 5.3
CVE-2022-48318

No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended informa…

Mitigation only
Fix from $1,600 2023-02-20
Checkmk HIGH 7.8
CVE-2022-33912

A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise ed…

Mitigation only
Fix from $1,950 2022-06-17
Checkmk MEDIUM 5.4
CVE-2022-24565

Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XSS) vulnerability. The Alias o…

Mitigation only
Fix from $1,600 2022-02-24
Checkmk MEDIUM 5.4
CVE-2022-24566

In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when sh…

Mitigation only
Fix from $1,600 2022-02-24
Checkmk MEDIUM 5.9
CVE-2017-14955EPSS 12%

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to…

No fix yet
Fix from $1,600 2017-10-02