Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Checkmk HIGH 7.5
CVE-2025-1075

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials …

Fix: 2.1.0+
Fix from $1,950 2025-02-19
Checkmk MEDIUM 5.5
CVE-2024-47094

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets …

Mitigation only
Fix from $1,600 2024-11-29
Checkmk HIGH 7.5
CVE-2024-38863

Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to …

Mitigation only
Fix from $1,950 2024-10-14
Checkmk HIGH 7.5
CVE-2024-6747

Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive da…

Fix: 2.1.0+
Fix from $1,950 2024-10-10
Checkmk HIGH 8.8
CVE-2024-8606

Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication

Mitigation only
Fix from $1,950 2024-09-23
Checkmk MEDIUM 6.1
CVE-2024-38860

Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phish…

Mitigation only
Fix from $1,600 2024-09-17
Checkmk HIGH 7.4
CVE-2024-6572

Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2…

Mitigation only
Fix from $1,950 2024-09-09
Checkmk MEDIUM 6.1
CVE-2024-38858

Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.

Fix: 2.3.0+
Fix from $1,600 2024-09-02
Checkmk MEDIUM 6.1
CVE-2024-38859

XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users…

Mitigation only
Fix from $1,600 2024-08-26
Checkmk HIGH 7.8
CVE-2024-28829

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.…

Mitigation only
Fix from $1,950 2024-08-20
Checkmk MEDIUM 6.5
CVE-2024-6542

Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary …

Mitigation only
Fix from $1,600 2024-07-22
Checkmk HIGH 8.8
CVE-2024-28828

Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.

Mitigation only
Fix from $1,950 2024-07-10
Checkmk HIGH 7.8
CVE-2024-28827

Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a loca…

Fix: after 2.0.0
Fix from $1,950 2024-07-10
Checkmk MEDIUM 5.3
CVE-2024-6163

Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and acces…

Fix: after 2.0.0
Fix from $1,600 2024-07-08
Checkmk MEDIUM 5.4
CVE-2024-6052

Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elemen…

Fix: after 2.0.0
Fix from $1,600 2024-07-03
Checkmk MEDIUM 6.1
CVE-2024-38857

Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attackers to craft malicious links th…

Fix: after 2.0.0
Fix from $1,600 2024-07-02
Checkmk MEDIUM 5.4
CVE-2024-28831

Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injectin…

Fix: after 2.2.0
Fix from $1,600 2024-06-25
Checkmk MEDIUM 5.4
CVE-2024-5741

Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)

Fix: after 2.0.0
Fix from $1,600 2024-06-17
Checkmk HIGH 7.5
CVE-2024-28833

Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forc…

Mitigation only
Fix from $1,950 2024-06-10
Checkmk HIGH 8.1
CVE-2024-28826

Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allow…

Fix: after 2.0.0
Fix from $1,950 2024-05-29
Checkmk CRITICAL 9.8
CVE-2024-28825

Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in…

Fix: after 2.0.0
Fix from $2,300 2024-04-24
Checkmk MEDIUM 5.5
CVE-2024-3367

Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmq…

Fix: after 2.0.0
Fix from $1,600 2024-04-16
Checkmk MEDIUM 5.4
CVE-2024-2380

Stored XSS in graph rendering in Checkmk <2.3.0b4.

Mitigation only
Fix from $1,600 2024-04-05
Checkmk HIGH 7.8
CVE-2024-28824

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 …

Fix: after 2.0.0
Fix from $1,950 2024-03-22
Checkmk MEDIUM 6.7
CVE-2024-0638

Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 …

Fix: after 2.0.0
Fix from $1,600 2024-03-22
Checkmk HIGH 7.8
CVE-2024-0670

Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

Fix: 2.1.0+
Fix from $1,950 2024-03-11
Checkmk HIGH 7.8
CVE-2023-6735

Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Fix: after 2.0.0
Fix from $1,950 2024-01-12
Checkmk HIGH 7.8
CVE-2023-6740

Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Fix: after 2.0.0
Fix from $1,950 2024-01-12
Checkmk MEDIUM 6.5
CVE-2023-31211

Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials

Fix: after 2.0.0
Fix from $1,600 2024-01-12
Checkmk HIGH 7.8
CVE-2023-31210

Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via inject…

Mitigation only
Fix from $1,950 2023-12-13