CVE-2025-65000
- EPSS 0.18%
- Veröffentlicht 18.12.2025 14:15:59
- Zuletzt bearbeitet 23.12.2025 17:04:50
SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts ...
CVE-2025-64997
- EPSS 0.21%
- Veröffentlicht 18.12.2025 09:11:17
- Zuletzt bearbeitet 23.12.2025 17:03:40
Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view agent information via the REST API, which could lead to information disclosure.
CVE-2025-58121
- EPSS 0.17%
- Veröffentlicht 18.11.2025 15:11:35
- Zuletzt bearbeitet 24.11.2025 14:27:29
Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information
CVE-2025-58122
- EPSS 0.14%
- Veröffentlicht 18.11.2025 15:11:17
- Zuletzt bearbeitet 24.11.2025 13:58:28
Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the REST API, which could lead to unauthorized actions or information disclosure.
CVE-2025-64996
- EPSS 0.09%
- Veröffentlicht 18.11.2025 15:10:53
- Zuletzt bearbeitet 24.11.2025 14:13:26
In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially le...
CVE-2025-39663
- EPSS 0.56%
- Veröffentlicht 30.10.2025 10:43:08
- Zuletzt bearbeitet 03.12.2025 20:06:16
Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).
CVE-2025-39664
- EPSS 0.63%
- Veröffentlicht 09.10.2025 15:01:55
- Zuletzt bearbeitet 04.12.2025 20:37:25
Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.
CVE-2025-32919
- EPSS 0.24%
- Veröffentlicht 09.10.2025 15:01:42
- Zuletzt bearbeitet 04.12.2025 20:39:36
Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before 2.2.0p46, and all ve...
CVE-2025-32916
- EPSS 0.18%
- Veröffentlicht 09.10.2025 15:00:58
- Zuletzt bearbeitet 04.12.2025 20:44:21
Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various places suc...
CVE-2025-32918
- EPSS 0.33%
- Veröffentlicht 04.07.2025 08:15:25
- Zuletzt bearbeitet 22.08.2025 13:29:48
Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.