Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

126 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.34%—Checkmk5/4/202417/6/2026
Stored XSS in graph rendering in Checkmk <2.3.0b4.
AnalizadaAlta (7.8)0.18%—Checkmk22/3/202417/6/2026
Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.
AnalizadaBaja (3.3)0.25%—Checkmk22/3/202417/6/2026
Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list.
AnalizadaMedia (6.7)0.20%—Checkmk22/3/202417/6/2026
Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.
AnalizadaAlta (7.8)0.33%💥 PoCCheckmk11/3/202417/6/2026
Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges
ModificadaAlta (7.8)0.18%—CheckmkTribe29 Checkmk12/1/202417/6/2026
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
ModificadaAlta (7.8)0.28%—CheckmkTribe29 Checkmk12/1/202417/6/2026
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
ModificadaMedia (6.5)0.51%—CheckmkTribe29 Checkmk12/1/202417/6/2026
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
ModificadaAlta (7.8)0.54%—Checkmk13/12/202317/6/2026
Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries
ModificadaMedia (5.5)0.24%—Tribe29 Checkmk Appliance Firmware27/11/202317/6/2026
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.
ModificadaBaja (3.5)0.23%—Checkmk24/11/202317/6/2026
Cross-site Request Forgery (CSRF) in Checkmk < 2.2.0p15, < 2.1.0p37, <= 2.0.0p39 allow an authenticated attacker to delete user-messages for individual users.
ModificadaAlta (8.8)0.89%—Checkmk22/11/202317/6/2026
Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
ModificadaAlta (8.8)0.86%—Checkmk22/11/202317/6/2026
Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
ModificadaBaja (2.7)0.65%—Checkmk15/11/202317/6/2026
Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial denial of service of the UI via too long hostnames.
ModificadaAlta (8.8)1.1%—CheckmkTribe29 Checkmk10/8/202317/6/2026
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.
ModificadaMedia (6.1)0.41%—Checkmk1/8/202317/6/2026
Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
ModificadaMedia (4.3)0.50%—Checkmk26/6/202317/6/2026
User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.
ModificadaMedia (4.3)0.59%—CheckmkTribe29 Checkmk17/5/202317/6/2026
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
ModificadaAlta (8.8)0.97%—CheckmkTribe29 Checkmk17/5/202317/6/2026
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
ModificadaAlta (7.5)0.54%—Tribe29 Checkmk Appliance Firmware15/5/202317/6/2026
Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5.
ModificadaMedia (5.5)0.22%—Checkmk2/5/202317/6/2026
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
ModificadaMedia (6.1)0.41%—Tribe29 Checkmk Appliance Firmware20/4/202317/6/2026
Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.
ModificadaAlta (8.8)0.39%—Checkmk20/4/202317/6/2026
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges…
ModificadaMedia (5.5)0.22%—Tribe29 Checkmk Appliance Firmware18/4/202317/6/2026
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.
ModificadaAlta (8.8)0.68%—Tribe29 Checkmk18/4/202317/6/2026
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
Orbitaley — Vulnerabilidades