Checkmk GmbH
First CVE: Jan 9, 2023Active for: 4 years
115
CVEs Published
More CVEs Published than 71% of tracked CNAs
28.8
Avg CVEs / Year
More Avg CVEs / Year than 76% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 19% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Checkmk GmbH as a CNA, 86.1% affect products that Checkmk GmbH develops as a vendor.
86.1%
13.9%
Self-reported: 99Third-party: 16
Of all the CVEs published that affect products developed by Checkmk GmbH, 89.2% are self-published by Checkmk GmbH as a CNA.
89.2%
10.8%
Self-published: 99Published by other CNAs: 12
Trends Over Time
The number and severity of CVEs published by Checkmk GmbH over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2023
3 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by Checkmk GmbH as a CNA, regardless of affected vendor or product.
115 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33456HIGH Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Live | Apr 10, 2026 | 7.6 | 30 | NO | NO |
CVE-2024-47091HIGH Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whos | May 13, 2026 | 7.8 | 29 | NO | NO |
CVE-2022-48317CRITICAL Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when commu | Feb 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-46836HIGH PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP | Feb 20, 2023 | 8.8 | 29 | NO | NO |
CVE-2026-24096HIGH Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged | Apr 1, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-8593MEDIUM Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and | Jul 21, 2026 | 5.3 | 27 | NO | NO |
CVE-2026-14852MEDIUM Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary c | Jul 14, 2026 | 5.2 | 27 | NO | NO |
CVE-2025-39663HIGH Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site | Oct 30, 2025 | 8.4 | 27 | NO | NO |
CVE-2024-28825CRITICAL Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitate | Apr 24, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-31208HIGH Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for au | May 17, 2023 | 8.8 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA115 CVEs
57%
36%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local27 (23.5%)
Network88 (76.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low107 (93.0%)
High8 (7.0%)
Unknown0 (0.0%)
User Interaction
None87 (75.7%)
Unknown0 (0.0%)
Required28 (24.3%)
Privileges Required
Low68 (59.1%)
High10 (8.7%)
None37 (32.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (115 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Checkmk GmbH as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Checkmk GmbH as a CNA — matched by CVE ID, not by organization name.