Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-7186 Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboar… Checkmk Mitigation only Fix from $1,6002026-06-08 MEDIUM 5.4 CVE-2026-8833 Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions a… Checkmk Mitigation only Fix from $1,6002026-06-08 MEDIUM 5.3 CVE-2026-7765 Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creat… Checkmk Mitigation only Fix from $1,6002026-06-08 HIGH 7.8 CVE-2024-47091 Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able t… Checkmk Mitigation only Fix from $1,9502026-05-13 HIGH 7.6 CVE-2026-33456 Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification tes… Checkmk Mitigation only Fix from $1,9502026-04-10 MEDIUM 6.3 CVE-2026-33457 Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Live… Checkmk Mitigation only Fix from $1,6002026-04-10 MEDIUM 6.3 CVE-2026-33455 Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search … Checkmk Mitigation only Fix from $1,6002026-04-10 MEDIUM 5.4 CVE-2026-3466 Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and … Checkmk Mitigation only Fix from $1,6002026-04-07 HIGH 7.3 CVE-2025-39666 Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.… Checkmk Mitigation only Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-24096 Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version… Checkmk Mitigation only Fix from $1,9502026-04-01 MEDIUM 5.4 CVE-2026-33276 Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to ex… Checkmk Mitigation only Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2026-20915 Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes… Checkmk Mitigation only Fix from $1,6002026-03-31 HIGH 7.2 CVE-2025-64998 Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hij… Checkmk Mitigation only Fix from $1,9502026-03-24 MEDIUM 5.4 CVE-2026-3103 A logic error in the remove_password() function in Checkmk GmbH's Checkmk versions <2.4.0p23, <2.3.0p43, and 2.2.0 (EOL) allows a low-privileged user… Checkmk Mitigation only Fix from $1,6002026-03-04 MEDIUM 5.4 CVE-2025-64999 Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's… Checkmk Mitigation only Fix from $1,6002026-02-26 MEDIUM 5.3 CVE-2025-65000 SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of C… Checkmk Mitigation only Fix from $1,6002025-12-18 MEDIUM 6.5 CVE-2025-64997 Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view agent information via the RE… Checkmk Mitigation only Fix from $1,6002025-12-18 MEDIUM 5.4 CVE-2025-58121 Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged us… Checkmk 2.4.0+ Fix from $1,6002025-11-18 MEDIUM 5.4 CVE-2025-58122 Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the RES… Checkmk Mitigation only Fix from $1,6002025-11-18 HIGH 8.4 CVE-2025-39663 Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into serv… Checkmk 2.3.0+ Fix from $1,9502025-10-30 HIGH 7.8 CVE-2025-32919 Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Ch… Checkmk 2.2.0+ Fix from $1,9502025-10-09 MEDIUM 6.5 CVE-2025-39664 Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define… Checkmk 2.2.0+ Fix from $1,6002025-10-09 HIGH 8.8 CVE-2025-32918 Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p… Checkmk Mitigation only Fix from $1,9502025-07-04 MEDIUM 5.5 CVE-2025-32915 Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42… Checkmk Mitigation only Fix from $1,6002025-05-22 HIGH 8.8 CVE-2025-1712 Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitra… Checkmk 2.2.0+ Fix from $1,9502025-05-21 HIGH 8.8 CVE-2025-32917 Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with writ… Checkmk Mitigation only Fix from $1,9502025-05-13 MEDIUM 5.3 CVE-2025-3506 Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows att… Checkmk after 2.3.0 Fix from $1,6002025-05-08 HIGH 7.5 CVE-2025-2092 Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site auth… Checkmk 2.1.0+ Fix from $1,9502025-04-22 HIGH 8.8 CVE-2024-38865 Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (… Checkmk 2.1.0+ Fix from $1,9502025-04-10 MEDIUM 5.3 CVE-2025-2596 Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL) Checkmk 2.1.0+ Fix from $1,6002025-03-26