Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.34% | — | Checkmk | 5/4/2024 | 17/6/2026 | Stored XSS in graph rendering in Checkmk <2.3.0b4. | |
| Analizada | Alta (7.8) | 0.18% | — | Checkmk | 22/3/2024 | 17/6/2026 | Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges. | |
| Analizada | Baja (3.3) | 0.25% | — | Checkmk | 22/3/2024 | 17/6/2026 | Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list. | |
| Analizada | Media (6.7) | 0.20% | — | Checkmk | 22/3/2024 | 17/6/2026 | Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges. | |
| Analizada | Alta (7.8) | 0.33% | 💥 PoC | Checkmk | 11/3/2024 | 17/6/2026 | Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges | |
| Modificada | Alta (7.8) | 0.18% | — | CheckmkTribe29 Checkmk | 12/1/2024 | 17/6/2026 | Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges | |
| Modificada | Alta (7.8) | 0.28% | — | CheckmkTribe29 Checkmk | 12/1/2024 | 17/6/2026 | Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges | |
| Modificada | Media (6.5) | 0.51% | — | CheckmkTribe29 Checkmk | 12/1/2024 | 17/6/2026 | Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials | |
| Modificada | Alta (7.8) | 0.54% | — | Checkmk | 13/12/2023 | 17/6/2026 | Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries | |
| Modificada | Media (5.5) | 0.24% | — | Tribe29 Checkmk Appliance Firmware | 27/11/2023 | 17/6/2026 | Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files. | |
| Modificada | Baja (3.5) | 0.23% | — | Checkmk | 24/11/2023 | 17/6/2026 | Cross-site Request Forgery (CSRF) in Checkmk < 2.2.0p15, < 2.1.0p37, <= 2.0.0p39 allow an authenticated attacker to delete user-messages for individual users. | |
| Modificada | Alta (8.8) | 0.89% | — | Checkmk | 22/11/2023 | 17/6/2026 | Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users. | |
| Modificada | Alta (8.8) | 0.86% | — | Checkmk | 22/11/2023 | 17/6/2026 | Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users. | |
| Modificada | Baja (2.7) | 0.65% | — | Checkmk | 15/11/2023 | 17/6/2026 | Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial denial of service of the UI via too long hostnames. | |
| Modificada | Alta (8.8) | 1.1% | — | CheckmkTribe29 Checkmk | 10/8/2023 | 17/6/2026 | Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users. | |
| Modificada | Media (6.1) | 0.41% | — | Checkmk | 1/8/2023 | 17/6/2026 | Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30. | |
| Modificada | Media (4.3) | 0.50% | — | Checkmk | 26/6/2023 | 17/6/2026 | User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames. | |
| Modificada | Media (4.3) | 0.59% | — | CheckmkTribe29 Checkmk | 17/5/2023 | 17/6/2026 | Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs. | |
| Modificada | Alta (8.8) | 0.97% | — | CheckmkTribe29 Checkmk | 17/5/2023 | 17/6/2026 | Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users. | |
| Modificada | Alta (7.5) | 0.54% | — | Tribe29 Checkmk Appliance Firmware | 15/5/2023 | 17/6/2026 | Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5. | |
| Modificada | Media (5.5) | 0.22% | — | Checkmk | 2/5/2023 | 17/6/2026 | Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log. | |
| Modificada | Media (6.1) | 0.41% | — | Tribe29 Checkmk Appliance Firmware | 20/4/2023 | 17/6/2026 | Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4. | |
| Modificada | Alta (8.8) | 0.39% | — | Checkmk | 20/4/2023 | 17/6/2026 | Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges… | |
| Modificada | Media (5.5) | 0.22% | — | Tribe29 Checkmk Appliance Firmware | 18/4/2023 | 17/6/2026 | Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files. | |
| Modificada | Alta (8.8) | 0.68% | — | Tribe29 Checkmk | 18/4/2023 | 17/6/2026 | Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions. |