Check Mk Project maintains a monitoring and observability platform that, despite a narrow product footprint, is widely deployed across enterprise infrastructure environments to provide centralized visibility into system health and performance. The recurring vulnerability pattern centers on its web-facing interface, with a durable signal in input-handling and code-generation weaknesses including cross-site scripting, code injection, CSRF, improper input validation, and symlink-following issues that are characteristic of complex web applications handling untrusted data and system interactions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Check Mk Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5340HIGH The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted | Sep 2, 2014 | 9.3 | 31 | NO | NO |
CVE-2014-2330MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authentication of users for requests | Aug 31, 2015 | 6.8 | 23 | NO | NO |
CVE-2014-2331HIGH Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. NOTE: this can be exploited by | Aug 31, 2015 | 8.5 | 22 | NO | NO |
CVE-2017-9781MEDIUM A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript v | Jun 21, 2017 | 6.1 | 21 | NO | NO |
CVE-2014-5339MEDIUM Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk files) to arbitrary locations via vectors related to row sele | Sep 2, 2014 | 4.9 | 20 | NO | NO |
CVE-2014-0243MEDIUM Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job. | Jul 19, 2018 | 5.5 | 17 | NO | NO |
CVE-2017-11507MEDIUM A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.2.8x prior to 1.2.8p25 and 1.4.0x prior to 1.4.0p9, allowing an unauthenticated attacker to inject arbitrar | Dec 11, 2017 | 6.1 | 17 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in the multisite component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allow remote authenticated users to inject arbitr | Aug 22, 2014 | 3.5 | 17 | NO | NO |
CVE-2014-2332MEDIUM Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to "Insecure Direct Obje | Aug 31, 2015 | 5.5 | 16 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject arbitrary web script or HTML via | Aug 31, 2015 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Check Mk Project.
Media articles that mention a CVE ID that affects a product developed by Check Mk Project — matched by CVE ID, not by vendor name.