← Back

Checkmk

checkmk

108 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Checkmk
checkmk

CVEs (108)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Checkmk
1Checkmk
Jun 17, 2026
Oct 14, 2024
5.1 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to be written to audit l...Show more
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to be written to audit log files accessible to administrators.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Oct 10, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data
1Checkmk
1Checkmk
Jun 17, 2026
Sep 23, 2024
9.2 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication
1Checkmk
1Checkmk
Jun 17, 2026
Sep 17, 2024
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.
1Checkmk
1Checkmk
Jun 17, 2026
Sep 9, 2024
6.3 MEDIUM· v4
7.4 HIGH· v3
N/A· v2
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to i...Show more
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept trafficShow less
1Checkmk
1Checkmk
Jun 17, 2026
Sep 2, 2024
2.3 LOW· v4
6.1 MEDIUM· v3
N/A· v2
Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.
1Checkmk
1Checkmk
Jun 17, 2026
Aug 26, 2024
4.8 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA c...Show more
XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view page was cloned by other users.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Aug 20, 2024
5.2 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges.
1Checkmk
1Checkmk
Jun 17, 2026
Jul 22, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.
1Checkmk
1Checkmk
Jun 17, 2026
Jul 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.
1Checkmk
1Checkmk
Jun 17, 2026
Jul 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a local attacker to gain SYSTEM privileges.
1Checkmk
1Checkmk
Jun 17, 2026
Jul 8, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data
1Checkmk
1Checkmk
Jun 17, 2026
Jul 3, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements
1Checkmk
1Checkmk
Jun 17, 2026
Jul 2, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attackers to craft malicious links that can facilitate phishing attacks.
1Checkmk
1Checkmk
Jun 17, 2026
Jun 26, 2024
N/A· v4
2.7 LOW· v3
N/A· v2
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <=2.0.0p39 (EOL) causes automation user secrets to be written to audit log files accessible to admini...Show more
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <=2.0.0p39 (EOL) causes automation user secrets to be written to audit log files accessible to administrators.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Jun 25, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements i...Show more
Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Jun 25, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirm...Show more
Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.Show less
1Checkmk
1Checkmk
Jun 17, 2026
Jun 17, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)
1Checkmk
1Checkmk
Jun 17, 2026
Jun 10, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms.
1Checkmk
1Checkmk
Jun 17, 2026
May 29, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read...Show more
Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.Show less