Search CVE reports


Toggle filters

11 – 20 of 109 results


CVE-2025-39663

Medium priority
Needs evaluation

Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39,...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Needs evaluation
Show less packages

CVE-2025-39664

Medium priority
Needs evaluation

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Needs evaluation
Show less packages

CVE-2025-32919

Medium priority
Not affected

Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Not affected
Show less packages

CVE-2025-32916

Medium priority
Needs evaluation

Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Needs evaluation
Show less packages

CVE-2025-32918

Medium priority
Needs evaluation

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Needs evaluation
Show less packages

CVE-2025-32915

Medium priority
Needs evaluation

Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-1712

Medium priority
Needs evaluation

Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitrary files

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-32917

Medium priority
Needs evaluation

Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with write access to JAVA_HOME/bin directory to escalate privileges.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-3506

Medium priority
Needs evaluation

Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that could contain secrets.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-2092

Medium priority
Needs evaluation

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site authentication secrets to be written to log files accessible to administrators.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Not in release Needs evaluation
Show less packages