Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-31891
Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially af…
Cockpit
2.13.5+
MEDIUM 6.1
CVE-2025-7053
A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/u…
Cockpit
after 2.11.3
CRITICAL 9.8
CVE-2024-4825
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post reque…
Cockpit
Mitigation only
MEDIUM 5.4
CVE-2024-2001
A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infect…
Cockpit
Mitigation only
MEDIUM 6.1
CVE-2023-41564
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a …
Cockpit
Mitigation only
MEDIUM 6.1
CVE-2023-4451
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
Cockpit
after 2.6.3
MEDIUM 6.1
CVE-2023-4432
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
Cockpit
after 2.6.3
MEDIUM 5.4
CVE-2023-4433
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
Cockpit
after 2.6.3
MEDIUM 5.4
CVE-2023-4395
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
Cockpit
2.6.4+
MEDIUM 6.1
CVE-2023-4321
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.
Cockpit
2.4.3+
HIGH 8.8
CVE-2023-4195
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
Cockpit
2.6.3+
MEDIUM 5.4
CVE-2023-4196
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
Cockpit
2.6.3+
HIGH 8.8
CVE-2023-37650
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
Cockpit
after 2.5.2
HIGH 7.5
CVE-2023-37649
Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.
Cockpit
after 2.5.2
HIGH 8.8
CVE-2023-1313
Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.
Cockpit
after 2.4.0
MEDIUM 5.5
CVE-2023-1160
Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.
Cockpit
after 2.3.9
MEDIUM 6.1
CVE-2021-32857
Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML s…
Cockpit
after 0.12.2
MEDIUM 5.4
CVE-2023-0780
Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.
Cockpit
2.3.9+
HIGH 8.8
CVE-2023-0759
Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
Cockpit
2.3.8+
HIGH 8.8
CVE-2022-2818
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
Cockpit
2.2.2+
CRITICAL 9.8
CVE-2022-2713
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
Cockpit
2.2.0+
CRITICAL 9.8
CVE-2020-35131EPSS 51%
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/…
Cockpit
0.6.1+
CRITICAL 9.8
CVE-2020-35846EPSS 93%
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
Cockpit
0.11.2+
CRITICAL 9.8
CVE-2020-35847EPSS 98%
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
Cockpit
0.11.2+
CRITICAL 9.8
CVE-2020-35848EPSS 75%
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
Cockpit
0.11.2+
MEDIUM 6.1
CVE-2020-14408
An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of ar…
Cockpit
No fix yet
CRITICAL 9.8
CVE-2018-15540
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended …
Cockpit
No fix yet
HIGH 8.8
CVE-2018-15539
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.
Cockpit
Mitigation only
MEDIUM 6.1
CVE-2018-15538
Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.
Cockpit
No fix yet
CRITICAL 9.1
CVE-2017-14611
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the ur…
Cockpit
No fix yet