Checkmk / Checkmk
108 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-90990 | Livestatus injection via monitoring filter values | MEDIUM | 5.3 | Sep 22, 2026 |
| CVE-2026-92882 | Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses | LOW | 2.3 | Sep 22, 2026 |
| CVE-2026-77021 | Missing decompression size limit in agent receiver allows memory exhaustion via push agent data | MEDIUM | 5.3 | Sep 21, 2026 |
| CVE-2026-15937 | Agent receiver certificate confusion allows authentication with a certificate issued for another endpoint | MEDIUM | 5.3 | Sep 4, 2026 |
| CVE-2026-17548 | Missing authorization for viewing background jobs | MEDIUM | 5.3 | Aug 25, 2026 |
| CVE-2026-15576 | Agent receiver accepts mTLS requests without a client certificate | MEDIUM | 6.9 | Aug 21, 2026 |
| CVE-2026-7485 | Frozen BI aggregations leak host and service names to unauthorized users | LOW | 2.3 | Aug 20, 2026 |
| CVE-2026-15227 | Missing Authorization Allows Editing of Foreign Reports | MEDIUM | 5.3 | Jul 31, 2026 |
| CVE-2026-8593 | Fix Business Intelligence API Pack permission | MEDIUM | 5.3 | Jul 21, 2026 |
| CVE-2026-14852 | mk_sap_hana: Privilege escalation via crafted sapstartsrv process name | MEDIUM | 5.2 | Jul 14, 2026 |
| CVE-2026-9549 | Fix XSS in service discovery active check output | MEDIUM | 4.8 | Jun 8, 2026 |
| CVE-2026-8833 | XSS in urls | HIGH | 8.5 | Jun 8, 2026 |
| CVE-2026-8078 | Fix stored XSS in global settings change log | MEDIUM | 4.8 | Jun 8, 2026 |
| CVE-2026-7765 | User Messages widget leaked issuer messages on shared dashboards | MEDIUM | 6.3 | Jun 8, 2026 |
| CVE-2026-7186 | Fix stored XSS in URL dashboard widget via dangerous URI schemes | HIGH | 8.5 | Jun 8, 2026 |
| CVE-2024-47091 | Privilege escalation via mk_mysql agent plugin on Windows | MEDIUM | 5.2 | May 13, 2026 |
| CVE-2026-33457 | Potential livestatus injection in prediction graph page | MEDIUM | 5.3 | Apr 10, 2026 |
| CVE-2026-33456 | Potential livestatus injection in notification test | MEDIUM | 5.1 | Apr 10, 2026 |
| CVE-2026-33455 | Livestatus injection in monitoring quicksearch | MEDIUM | 5.3 | Apr 10, 2026 |
| CVE-2025-39666 | omd: Local privilege escalation when executing omd commands as root | CRITICAL | 9.3 | Apr 7, 2026 |
| CVE-2026-3466 | Cross-site scripting in dashlet title | HIGH | 8.5 | Apr 7, 2026 |
| CVE-2026-24096 | Insufficient permission validation on multiple REST API Quick Setup endpoints | MEDIUM | 5.3 | Apr 1, 2026 |
| CVE-2026-20915 | Stored cross-site scripting in Pending Changes sidebar | HIGH | 8.5 | Mar 31, 2026 |
| CVE-2026-33276 | XSS in Unified Search via Unescaped Host/Service Names | HIGH | 8.6 | Mar 31, 2026 |
| CVE-2025-64998 | Session hijacking via exposed session signing secret in distributed Checkmk setups | HIGH | 7.3 | Mar 24, 2026 |
Showing 1 to 25 of 108 CVEs