vciy

CVEs we hold for Checkmk

Records whose assigning authority named Checkmk as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9549Fix XSS in service discovery active check outputCheckmk
CVE-2026-8833XSS in urlsCheckmk
CVE-2026-8593Fix Business Intelligence API Pack permissionCheckmk
CVE-2026-8078Fix stored XSS in global settings change logCheckmk
CVE-2026-7765User Messages widget leaked issuer messages on shared dashboardsCheckmk
CVE-2026-7485Frozen BI aggregations leak host and service names to unauthorized usersCheckmk
CVE-2026-7186Fix stored XSS in URL dashboard widget via dangerous URI schemesCheckmk
CVE-2026-3466Cross-site scripting in dashlet titleCheckmk
CVE-2026-33457Potential livestatus injection in prediction graph pageCheckmk
CVE-2026-33456Potential livestatus injection in notification testCheckmk
CVE-2026-33455Livestatus injection in monitoring quicksearchCheckmk
CVE-2026-33276XSS in Unified Search via Unescaped Host/Service NamesCheckmk
CVE-2026-3103Deletion of passwords via RestApiCheckmk
CVE-2026-2859Unauthenticated Host Enumeration via Observable Response Discrepancy on Deploy Agent EndpointCheckmk
CVE-2026-24097Authenticated Host Enumeration via Observable Response Discrepancy on Agent Register Existing EndpointCheckmk
CVE-2026-24096Insufficient permission validation on multiple REST API Quick Setup endpointsCheckmk
CVE-2026-24095Missing Permission Check on Analyze Configuration PageCheckmk
CVE-2026-20915Stored cross-site scripting in Pending Changes sidebarCheckmk
CVE-2026-17548Missing authorization for viewing background jobsCheckmk
CVE-2026-15937Agent receiver certificate confusion allows authentication with a certificate issued for another endpointCheckmk
CVE-2026-15576Agent receiver accepts mTLS requests without a client certificateCheckmk
CVE-2026-15227Missing Authorization Allows Editing of Foreign ReportsCheckmk
CVE-2026-14852mk_sap_hana: Privilege escalation via crafted sapstartsrv process nameCheckmk
CVE-2025-65000Exposure of SSH Private Keys in Remote Alert Handlers (Linux) RuleCheckmk
CVE-2025-64999Cross-site scripting in HTML logs of Synthetic Monitoring test servicesCheckmk
CVE-2025-64998Session hijacking via exposed session signing secret in distributed Checkmk setupsCheckmk
CVE-2025-64997Insufficient permission validation when showing agent informationCheckmk
CVE-2025-64996Overly broad file permissions in the mk_inotify plugin allows reading and manipulating the plugin's outputCheckmk
CVE-2025-58122Insufficient permission validation when configuring notification parametersCheckmk
CVE-2025-58121Insufficient permission validation on multiple REST API endpointsCheckmk
CVE-2025-39666omd: Local privilege escalation when executing omd commands as rootCheckmk
CVE-2025-39664Path-Traversal in report schedulerCheckmk
CVE-2025-39663Cross Site Scripting through compromised remote siteCheckmk
CVE-2025-3506Potentially senitive path exposed via unauthenticated http routeCheckmk
CVE-2025-32919Privilege Escalation in Windows License plugin for Checkmk Windows AgentCheckmk
CVE-2025-32918Livestatus injection in autocomplete endpointCheckmk
CVE-2025-32917Privilege escalation in jar_signatureCheckmk
CVE-2025-32916Sensitive form data in URL query parametersCheckmk
CVE-2025-32915Sensitive data exposed during automatic agent updatesCheckmk
CVE-2025-2596Session logout can be overwritten by long lasting requestCheckmk
CVE-2025-2092Remote site authentication secrets written to web logCheckmk
CVE-2025-1712Arbitrary file write with vcrtraceCheckmk
CVE-2025-1075LDAP credentials logged to Apache error logCheckmk
CVE-2024-8606Fix 2FA bypass via RestAPICheckmk
CVE-2024-6747Information leak in mknotifydCheckmk
CVE-2024-6572Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'Checkmk
CVE-2024-6542Livestatus injection in mknotifydCheckmk
CVE-2024-6163local IP restriction of internal HTTP endpointsCheckmk
CVE-2024-6052XSS in SQL check parametersCheckmk
CVE-2024-5741XSS in inventory viewCheckmk
CVE-2024-47094Logging of sitesecret to automations logCheckmk
CVE-2024-47091Privilege escalation via mk_mysql agent plugin on WindowsCheckmk
CVE-2024-38865Livestatus command injection in RestAPICheckmk
CVE-2024-38864User-Readable Private Key in Windows AgentCheckmk
CVE-2024-38863CSRF token leaked in URL parametersCheckmk
CVE-2024-38862SNMP and IMPI secrets written to audit logCheckmk
CVE-2024-38860Reflected links in error message facilitate phishing attacksCheckmk
CVE-2024-38859XSS in view page with SLA columnCheckmk
CVE-2024-38858Cross-site scripting in Robotmk logs viewCheckmk
CVE-2024-38857Reflected links in visuals facilitate phishing attacksCheckmk
CVE-2024-3367Argument injection to runmqscCheckmk
CVE-2024-28833Missing brute-force protection for two factor authenticationCheckmk
CVE-2024-28832XSS in Crash Report PageCheckmk
CVE-2024-28831XSS in confirmation pop-upCheckmk
CVE-2024-28830Automation user secrets written to audit logCheckmk
CVE-2024-28829Privilege escalation in mk_informix pluginCheckmk
CVE-2024-288281-Click compromize via CSRFCheckmk
CVE-2024-28827Privilege escalation in Windows agentCheckmk
CVE-2024-28826Unrestricted upload and download paths in check_sftpCheckmk
CVE-2024-28825Brute-force protection ineffective for some login methodsCheckmk
CVE-2024-28824Privilege escalation in mk_informix pluginCheckmk
CVE-2024-2380XSS in graph renderingCheckmk
CVE-2024-1742Information disclosure in mk_oracle Checkmk agent pluginCheckmk
CVE-2024-13723Checkmk NagVis Remote Code ExecutionCheckmk NagVis
CVE-2024-13722Checkmk NagVis Reflected Cross-site ScriptingCheckmk NagVis
CVE-2024-0670Privilege escalation in windows agentCheckmk
CVE-2024-0638Privilege escalation in mk_oracle pluginsCheckmk
CVE-2023-6740Privilege escalation in jar_signatureCheckmk
CVE-2023-6735Privilege escalation in mk_tsmCheckmk
CVE-2023-6287Backup password in GET parameterCheckmk Appliance
CVE-2023-6251CSRF in delete_user_messageCheckmk
CVE-2023-6157Livestatus injection in ajax_searchCheckmk
CVE-2023-6156Livestatus injection in availability timelineCheckmk
CVE-2023-31211Disabled automation users could still authenticateCheckmk
CVE-2023-31210Privilege escalation in agent via LD_LIBRARY_PATHCheckmk
CVE-2023-31209Command injection via active checks and REST APICheckmk
CVE-2023-31208Livestatus command injection in RestAPICheckmk
CVE-2023-23549DoS via long hostnamesCheckmk
CVE-2023-23548XSS in business intelligenceCheckmk
CVE-2023-22348Reading host_configs does not honour contact groupsCheckmk

90 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.