Skip to content
Noroxi

Tribe29 records

18 published records for vendor tribe29.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
61.1%
Median publish → KEV
No record has entered KEV

All records

18 records
  • The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" file

    HighCVSS 8.8Proof of conceptEPSS 3%

    checkmk · checkmkMar 25, 2022

  • Command injection via active checks and REST API

    HighCVSS 8.8No exploitEPSS 1%

    checkmk · checkmkAug 10, 2023

  • Livestatus command injection in RestAPI

    HighCVSS 8.8No exploitEPSS 1%

    checkmk · checkmkMay 17, 2023

  • Privilege escalation in Checkmk Appliance

    HighCVSS 8.8No exploitEPSS 1%

    tribe29 · checkmkApr 18, 2023

  • CVE-2023-0284
    32Monitor

    Improper validation of LDAP user IDs

    HighCVSS 8.1No exploitEPSS 1%

    checkmk · checkmkJan 26, 2023

  • CVE-2023-6735
    31Monitor

    Privilege escalation in mk_tsm

    HighCVSS 7.8No exploitEPSS 0%

    checkmk · checkmkJan 12, 2024

  • A permission issue affects users that deployed the shipped version of the Checkmk Debian package.

    HighCVSS 7.8No exploitEPSS 0%

    checkmk · checkmkJun 17, 2022

  • CVE-2023-6740
    31Monitor

    Privilege escalation in jar_signature

    HighCVSS 7.8No exploitEPSS 0%

    checkmk · checkmkJan 12, 2024

  • Denial of service against webconf

    HighCVSS 7.5No exploitEPSS 1%

    tribe29 · checkmk appliance firmwareMay 15, 2023

  • Disabled automation users could still authenticate

    MediumCVSS 6.5No exploitEPSS 1%

    checkmk · checkmkJan 12, 2024

  • In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.

    MediumCVSS 6.7No exploitEPSS 0%

    checkmk · checkmkMay 20, 2022

  • CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated

    MediumCVSS 6.1Proof of conceptEPSS 1%

    checkmk · checkmkMar 25, 2022

  • Reflected Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    tribe29 · checkmk appliance firmwareApr 20, 2023

  • CVE-2023-6287
    22Monitor

    Backup password in GET parameter

    MediumCVSS 5.5No exploitEPSS 0%

    tribe29 · checkmk appliance firmwareNov 27, 2023

  • Site-Passwords in GET parameters

    MediumCVSS 5.5No exploitEPSS 0%

    tribe29 · checkmk appliance firmwareApr 18, 2023

  • CVE-2023-1768
    21Monitor

    Symmetric agent data encryption fails silently

    MediumCVSS 5.3No exploitEPSS 1%

    checkmk · checkmkApr 4, 2023

  • Email HTML Injection

    MediumCVSS 5.4No exploitEPSS 0%

    checkmk · checkmkMar 20, 2023

  • Reading host_configs does not honour contact groups

    MediumCVSS 4.3No exploitEPSS 1%

    checkmk · checkmkMay 17, 2023