CVE-2026-9549
- EPSS 0.14%
- Veröffentlicht 08.06.2026 12:07:12
- Zuletzt bearbeitet 08.06.2026 15:53:09
Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into c...
CVE-2026-8833
- EPSS 0.14%
- Veröffentlicht 08.06.2026 12:06:51
- Zuletzt bearbeitet 09.06.2026 14:49:31
Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: UR...
CVE-2026-8078
- EPSS 0.14%
- Veröffentlicht 08.06.2026 12:06:36
- Zuletzt bearbeitet 08.06.2026 15:53:41
Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that ex...
CVE-2026-7765
- EPSS 0.19%
- Veröffentlicht 08.06.2026 12:06:02
- Zuletzt bearbeitet 09.06.2026 14:49:38
Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share...
CVE-2026-7186
- EPSS 0.14%
- Veröffentlicht 08.06.2026 12:05:28
- Zuletzt bearbeitet 08.06.2026 15:53:35
Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes sc...
CVE-2024-47091
- EPSS 0.12%
- Veröffentlicht 13.05.2026 08:35:25
- Zuletzt bearbeitet 26.05.2026 08:18:53
Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whose name matches 'MySQL' or 'MariaDB' (or with write access to a binary ...
CVE-2026-33456
- EPSS 0.2%
- Veröffentlicht 10.04.2026 09:16:24
- Zuletzt bearbeitet 20.04.2026 17:10:06
Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description.
CVE-2026-33457
- EPSS 0.18%
- Veröffentlicht 10.04.2026 09:16:24
- Zuletzt bearbeitet 20.04.2026 17:09:23
Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service ...
CVE-2026-33455
- EPSS 0.18%
- Veröffentlicht 10.04.2026 09:16:23
- Zuletzt bearbeitet 20.04.2026 17:10:27
Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.
CVE-2025-39666
- EPSS 0.12%
- Veröffentlicht 07.04.2026 12:09:07
- Zuletzt bearbeitet 14.04.2026 15:39:05
Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site contex...