Checkmk

Checkmk

103 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 10.04.2026 09:16:24
  • Zuletzt bearbeitet 13.04.2026 15:02:06

Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description.

  • EPSS 0.04%
  • Veröffentlicht 10.04.2026 09:16:24
  • Zuletzt bearbeitet 13.04.2026 15:02:06

Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service ...

  • EPSS 0.04%
  • Veröffentlicht 10.04.2026 09:16:23
  • Zuletzt bearbeitet 13.04.2026 15:02:06

Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.

  • EPSS 0.01%
  • Veröffentlicht 07.04.2026 12:09:07
  • Zuletzt bearbeitet 14.04.2026 15:39:05

Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site contex...

  • EPSS 0.05%
  • Veröffentlicht 07.04.2026 12:08:50
  • Zuletzt bearbeitet 14.04.2026 15:39:45

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows an attacker with dashboard creation privileges to perform ...

  • EPSS 0.05%
  • Veröffentlicht 01.04.2026 10:07:21
  • Zuletzt bearbeitet 07.04.2026 20:51:23

Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain sensitive information

  • EPSS 0.03%
  • Veröffentlicht 31.03.2026 13:51:02
  • Zuletzt bearbeitet 02.04.2026 12:06:00

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in the browsers ...

  • EPSS 0.05%
  • Veröffentlicht 31.03.2026 13:44:17
  • Zuletzt bearbeitet 02.04.2026 12:05:12

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Unified Search f...

  • EPSS 0.05%
  • Veröffentlicht 24.03.2026 11:25:58
  • Zuletzt bearbeitet 24.03.2026 15:53:48

Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.

  • EPSS 0.04%
  • Veröffentlicht 13.03.2026 09:40:43
  • Zuletzt bearbeitet 18.03.2026 13:23:32

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deploy_agent endpoint, which coul...