Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-4825 A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post reque… Cockpit Mitigation only Fix from $2,3002024-05-14 MEDIUM 5.4 CVE-2024-2001 A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infect… Cockpit Mitigation only Fix from $1,6002024-02-29 MEDIUM 6.1 CVE-2023-41564 An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a … Cockpit Mitigation only Fix from $1,6002023-09-08 MEDIUM 6.1 CVE-2020-14408 An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of ar… Cockpit No fix yet Fix from $1,6002020-06-17 CRITICAL 9.8 CVE-2018-15540 Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended … Cockpit No fix yet Fix from $2,3002018-10-15 HIGH 8.8 CVE-2018-15539 Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc. Cockpit Mitigation only Fix from $1,9502018-10-15 MEDIUM 6.1 CVE-2018-15538 Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities. Cockpit No fix yet Fix from $1,6002018-10-15 CRITICAL 9.1 CVE-2017-14611 SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the ur… Cockpit No fix yet Fix from $2,3002018-04-10