Vulnerability index

Browse CVEs

47 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-28833 Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forc… Checkmk Mitigation only Fix from $1,9502024-06-10 MEDIUM 5.4 CVE-2024-2380 Stored XSS in graph rendering in Checkmk <2.3.0b4. Checkmk Mitigation only Fix from $1,6002024-04-05 HIGH 7.8 CVE-2023-31210 Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via inject… Checkmk Mitigation only Fix from $1,9502023-12-13 HIGH 8.8 CVE-2023-6156 Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbit… Checkmk Mitigation only Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-6157 Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatu… Checkmk Mitigation only Fix from $1,9502023-11-22 MEDIUM 5.5 CVE-2023-31207 Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret… Checkmk Mitigation only Fix from $1,6002023-05-02 HIGH 8.8 CVE-2022-46302 Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations… Checkmk Mitigation only Fix from $1,9502023-04-20 CRITICAL 9.8 CVE-2022-48317 Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use ex… Checkmk Mitigation only Fix from $2,3002023-02-20 HIGH 8.8 CVE-2022-46836 PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an atta… Checkmk No fix yet Fix from $1,9502023-02-20 HIGH 7.8 CVE-2022-47909 Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions o… Checkmk No fix yet Fix from $1,9502023-02-20 HIGH 7.5 CVE-2022-46303 Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Mana… Checkmk Mitigation only Fix from $1,9502023-02-20 MEDIUM 5.5 CVE-2022-48319 Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0… Checkmk Mitigation only Fix from $1,6002023-02-20 MEDIUM 5.3 CVE-2022-48318 No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended informa… Checkmk Mitigation only Fix from $1,6002023-02-20 HIGH 7.8 CVE-2022-33912 A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise ed… Checkmk Mitigation only Fix from $1,9502022-06-17 MEDIUM 5.4 CVE-2022-24565 Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XSS) vulnerability. The Alias o… Checkmk Mitigation only Fix from $1,6002022-02-24 MEDIUM 5.4 CVE-2022-24566 In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when sh… Checkmk Mitigation only Fix from $1,6002022-02-24 MEDIUM 5.9 CVE-2017-14955EPSS 12% Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to… Checkmk No fix yet Fix from $1,6002017-10-02