Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Checkmk MEDIUM 5.4
CVE-2026-7186

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboar…

Mitigation only
Fix from $1,600 2026-06-08
Checkmk MEDIUM 5.4
CVE-2026-8833

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions a…

Mitigation only
Fix from $1,600 2026-06-08
Checkmk MEDIUM 5.3
CVE-2026-7765

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creat…

Mitigation only
Fix from $1,600 2026-06-08
Checkmk HIGH 7.8
CVE-2024-47091

Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able t…

Mitigation only
Fix from $1,950 2026-05-13
Checkmk HIGH 7.6
CVE-2026-33456

Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification tes…

Mitigation only
Fix from $1,950 2026-04-10
Checkmk MEDIUM 6.3
CVE-2026-33457

Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Live…

Mitigation only
Fix from $1,600 2026-04-10
Checkmk MEDIUM 6.3
CVE-2026-33455

Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search …

Mitigation only
Fix from $1,600 2026-04-10
Checkmk MEDIUM 5.4
CVE-2026-3466

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and …

Mitigation only
Fix from $1,600 2026-04-07
Checkmk HIGH 7.3
CVE-2025-39666

Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.…

Mitigation only
Fix from $1,950 2026-04-07
Checkmk HIGH 8.8
CVE-2026-24096

Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version…

Mitigation only
Fix from $1,950 2026-04-01
Checkmk MEDIUM 5.4
CVE-2026-33276

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to ex…

Mitigation only
Fix from $1,600 2026-03-31
Checkmk MEDIUM 5.4
CVE-2026-20915

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes…

Mitigation only
Fix from $1,600 2026-03-31
Checkmk HIGH 7.2
CVE-2025-64998

Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hij…

Mitigation only
Fix from $1,950 2026-03-24
Checkmk MEDIUM 5.4
CVE-2026-3103

A logic error in the remove_password() function in Checkmk GmbH's Checkmk versions <2.4.0p23, <2.3.0p43, and 2.2.0 (EOL) allows a low-privileged user…

Mitigation only
Fix from $1,600 2026-03-04
Checkmk MEDIUM 5.4
CVE-2025-64999

Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's…

Mitigation only
Fix from $1,600 2026-02-26
Checkmk MEDIUM 5.3
CVE-2025-65000

SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of C…

Mitigation only
Fix from $1,600 2025-12-18
Checkmk MEDIUM 6.5
CVE-2025-64997

Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view agent information via the RE…

Mitigation only
Fix from $1,600 2025-12-18
Checkmk MEDIUM 5.4
CVE-2025-58121

Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged us…

Fix: 2.4.0+
Fix from $1,600 2025-11-18
Checkmk MEDIUM 5.4
CVE-2025-58122

Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the RES…

Mitigation only
Fix from $1,600 2025-11-18
Checkmk HIGH 8.4
CVE-2025-39663

Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into serv…

Fix: 2.3.0+
Fix from $1,950 2025-10-30
Checkmk HIGH 7.8
CVE-2025-32919

Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Ch…

Fix: 2.2.0+
Fix from $1,950 2025-10-09
Checkmk MEDIUM 6.5
CVE-2025-39664

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define…

Fix: 2.2.0+
Fix from $1,600 2025-10-09
Checkmk HIGH 8.8
CVE-2025-32918

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p…

Mitigation only
Fix from $1,950 2025-07-04
Checkmk MEDIUM 5.5
CVE-2025-32915

Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42…

Mitigation only
Fix from $1,600 2025-05-22
Checkmk HIGH 8.8
CVE-2025-1712

Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitra…

Fix: 2.2.0+
Fix from $1,950 2025-05-21
Checkmk HIGH 8.8
CVE-2025-32917

Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with writ…

Mitigation only
Fix from $1,950 2025-05-13
Checkmk MEDIUM 5.3
CVE-2025-3506

Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows att…

Fix: after 2.3.0
Fix from $1,600 2025-05-08
Checkmk HIGH 7.5
CVE-2025-2092

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site auth…

Fix: 2.1.0+
Fix from $1,950 2025-04-22
Checkmk HIGH 8.8
CVE-2024-38865

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (…

Fix: 2.1.0+
Fix from $1,950 2025-04-10
Checkmk MEDIUM 5.3
CVE-2025-2596

Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)

Fix: 2.1.0+
Fix from $1,600 2025-03-26