Skip to content
Noroxi

Checkmk records

108 published records for vendor checkmk.

All records

108 records
  • Brute-force protection ineffective for some login methods

    CriticalCVSS 9.8No exploitEPSS 1%

    checkmk · checkmkApr 24, 2024

  • Insecure Termination of RestAPI Session Tokens

    CriticalCVSS 9.8No exploitEPSS 0%

    checkmk · checkmkFeb 20, 2023

  • omd: Local privilege escalation when executing omd commands as root

    CriticalCVSS 9.3No exploitEPSS 0%

    checkmk · checkmkApr 7, 2026

  • The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by

    HighCVSS 8.8Proof of conceptEPSS 4%

    checkmk · checkmkMar 25, 2022

  • The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" file

    HighCVSS 8.8Proof of conceptEPSS 3%

    checkmk · checkmkMar 25, 2022

  • CVE-2024-8606
    36Monitor

    Fix 2FA bypass via RestAPI

    CriticalCVSS 9.2No exploitEPSS 0%

    checkmk · checkmkSep 23, 2024

  • PHP code injection in watolib

    HighCVSS 8.8No exploitEPSS 1%

    checkmk · checkmkFeb 20, 2023

  • Command injection via active checks and REST API

    HighCVSS 8.8No exploitEPSS 1%

    checkmk · checkmkAug 10, 2023

  • Livestatus command injection in RestAPI

    HighCVSS 8.8No exploitEPSS 1%

    checkmk · checkmkMay 17, 2023

  • CVE-2023-6157
    35Monitor

    Livestatus injection in ajax_search

    HighCVSS 8.8No exploitEPSS 1%

    checkmk · checkmkNov 22, 2023

  • CVE-2023-6156
    35Monitor

    Livestatus injection in availability timeline

    HighCVSS 8.8No exploitEPSS 1%

    checkmk · checkmkNov 22, 2023

  • Remote Code Execution with Root Privileges via Broad Apache Permissions

    HighCVSS 8.8No exploitEPSS 0%

    checkmk · checkmkApr 20, 2023

  • Privilege Escalation in Windows License plugin for Checkmk Windows Agent

    HighCVSS 8.8No exploitEPSS 0%

    checkmk · checkmkOct 9, 2025

  • 1-Click compromize via CSRF

    HighCVSS 8.8No exploitEPSS 0%

    checkmk · checkmkJul 10, 2024

  • CVE-2025-1712
    34Monitor

    Arbitrary file write with vcrtrace

    HighCVSS 8.7No exploitEPSS 1%

    checkmk · checkmkMay 21, 2025

  • Cross Site Scripting through compromised remote site

    HighCVSS 8.5No exploitEPSS 1%

    checkmk · checkmkOct 30, 2025

  • CVE-2026-3466
    34Monitor

    Cross-site scripting in dashlet title

    HighCVSS 8.5No exploitEPSS 0%

    checkmk · checkmkApr 7, 2026

  • CVE-2026-8833
    34Monitor

    Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 v

    HighCVSS 8.5No exploitEPSS 0%

    checkmk · checkmkJun 8, 2026

  • XSS in Unified Search via Unescaped Host/Service Names

    HighCVSS 8.6No exploitEPSS 0%

    checkmk · checkmkMar 31, 2026

  • CVE-2026-7186
    34Monitor

    Fix stored XSS in URL dashboard widget via dangerous URI schemes

    HighCVSS 8.5No exploitEPSS 0%

    checkmk · checkmkJun 8, 2026

  • Stored cross-site scripting in Pending Changes sidebar

    HighCVSS 8.5No exploitEPSS 0%

    checkmk · checkmkMar 31, 2026

  • CVE-2023-0284
    32Monitor

    Improper validation of LDAP user IDs

    HighCVSS 8.1No exploitEPSS 1%

    checkmk · checkmkJan 26, 2023

  • Unrestricted upload and download paths in check_sftp

    HighCVSS 8.1No exploitEPSS 0%

    checkmk · checkmkMay 29, 2024

  • Privilege escalation in agent via LD_LIBRARY_PATH

    HighCVSS 7.8No exploitEPSS 1%

    checkmk · checkmkDec 13, 2023

  • LQL Injection in Livestatus HTTP headers

    HighCVSS 7.8No exploitEPSS 0%

    checkmk · checkmkFeb 20, 2023