Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tribe29

First CVE: Mar 25, 2022Active for: 4 yearsTotal CVEs: 32
35.9
VTI Score
Medium

Tribe29 develops Checkmk, a widely deployed infrastructure monitoring and observability platform used to track systems, networks, and applications at scale. The vendor's vulnerability exposure centers on its core monitoring product and associated appliance firmware, with recurring weaknesses in web-layer input handling, privilege boundaries, and information disclosure—typical of application software serving as a central management point. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
5.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tribe29 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2022
4 years ago
Most Recent CVE
Jan 12, 2024
924 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-40905HIGH
The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making
Mar 25, 20228.832NONO
CVE-2022-48317CRITICAL
Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when commu
Feb 20, 20239.829NONO
CVE-2022-46836HIGH
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP
Feb 20, 20238.829NONO
CVE-2023-31208HIGH
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for au
May 17, 20238.827NONO
CVE-2023-22294HIGH
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
Apr 18, 20238.826NONO
CVE-2023-0284HIGH
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0
Jan 26, 20238.125NONO
CVE-2022-33912HIGH
A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected.
Jun 17, 20227.825NONO
CVE-2023-31209HIGH
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.
Aug 10, 20238.824NONO
CVE-2023-22318HIGH
Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5.
May 15, 20237.524NONO
CVE-2022-47909HIGH
Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an
Feb 20, 20237.824NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
50%
44%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (37.5%)
Network20 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (96.9%)
High1 (3.1%)
Unknown0 (0.0%)
User Interaction
None27 (84.4%)
Unknown0 (0.0%)
Required5 (15.6%)
Privileges Required
Low22 (68.8%)
High2 (6.3%)
None8 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tribe29.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tribe29 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tribe29's Products

View all 2 CNAs →

Top CWEs