Checkmk GmbH

First CVE: Jan 9, 2023Active for: 4 years
115
CVEs Published
More CVEs Published than 71% of tracked CNAs
28.8
Avg CVEs / Year
More Avg CVEs / Year than 76% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 19% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Checkmk GmbH as a CNA, 86.1% affect products that Checkmk GmbH develops as a vendor.

86.1%
13.9%
Self-reported: 99Third-party: 16

Of all the CVEs published that affect products developed by Checkmk GmbH, 89.2% are self-published by Checkmk GmbH as a CNA.

89.2%
10.8%
Self-published: 99Published by other CNAs: 12

Trends Over Time

The number and severity of CVEs published by Checkmk GmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2023
3 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Checkmk GmbH as a CNA, regardless of affected vendor or product.

115 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Live
Apr 10, 20267.630NONO
Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whos
May 13, 20267.829NONO
Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when commu
Feb 20, 20239.829NONO
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP
Feb 20, 20238.829NONO
Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged
Apr 1, 20268.828NONO
Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and
Jul 21, 20265.327NONO
Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary c
Jul 14, 20265.227NONO
Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site
Oct 30, 20258.427NONO
Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitate
Apr 24, 20249.827NONO
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for au
May 17, 20238.827NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA115 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local27 (23.5%)
Network88 (76.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low107 (93.0%)
High8 (7.0%)
Unknown0 (0.0%)
User Interaction
None87 (75.7%)
Unknown0 (0.0%)
Required28 (24.3%)
Privileges Required
Low68 (59.1%)
High10 (8.7%)
None37 (32.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (115 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Checkmk GmbH as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Checkmk GmbH as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs