Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-31891 Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially af… Cockpit 2.13.5+ Fix from $1,6002026-03-18 MEDIUM 6.1 CVE-2025-7053 A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/u… Cockpit after 2.11.3 Fix from $1,6002025-07-04 CRITICAL 9.8 CVE-2024-4825 A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post reque… Cockpit Mitigation only Fix from $2,3002024-05-14 MEDIUM 5.4 CVE-2024-2001 A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infect… Cockpit Mitigation only Fix from $1,6002024-02-29 MEDIUM 6.1 CVE-2023-41564 An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a … Cockpit Mitigation only Fix from $1,6002023-09-08 MEDIUM 6.1 CVE-2023-4451 Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. Cockpit after 2.6.3 Fix from $1,6002023-08-20 MEDIUM 6.1 CVE-2023-4432 Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. Cockpit after 2.6.3 Fix from $1,6002023-08-19 MEDIUM 5.4 CVE-2023-4433 Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. Cockpit after 2.6.3 Fix from $1,6002023-08-19 MEDIUM 5.4 CVE-2023-4395 Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. Cockpit 2.6.4+ Fix from $1,6002023-08-17 MEDIUM 6.1 CVE-2023-4321 Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3. Cockpit 2.4.3+ Fix from $1,6002023-08-14 HIGH 8.8 CVE-2023-4195 PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. Cockpit 2.6.3+ Fix from $1,9502023-08-06 MEDIUM 5.4 CVE-2023-4196 Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. Cockpit 2.6.3+ Fix from $1,6002023-08-06 HIGH 8.8 CVE-2023-37650 A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands. Cockpit after 2.5.2 Fix from $1,9502023-07-20 HIGH 7.5 CVE-2023-37649 Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data. Cockpit after 2.5.2 Fix from $1,9502023-07-20 HIGH 8.8 CVE-2023-1313 Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1. Cockpit after 2.4.0 Fix from $1,9502023-03-10 MEDIUM 5.5 CVE-2023-1160 Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0. Cockpit after 2.3.9 Fix from $1,6002023-03-03 MEDIUM 6.1 CVE-2021-32857 Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML s… Cockpit after 0.12.2 Fix from $1,6002023-02-21 MEDIUM 5.4 CVE-2023-0780 Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev. Cockpit 2.3.9+ Fix from $1,6002023-02-11 HIGH 8.8 CVE-2023-0759 Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8. Cockpit 2.3.8+ Fix from $1,9502023-02-09 HIGH 8.8 CVE-2022-2818 Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2. Cockpit 2.2.2+ Fix from $1,9502022-08-15 CRITICAL 9.8 CVE-2022-2713 Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0. Cockpit 2.2.0+ Fix from $2,3002022-08-08 CRITICAL 9.8 CVE-2020-35131EPSS 51% Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/… Cockpit 0.6.1+ Fix from $2,3002021-01-08 CRITICAL 9.8 CVE-2020-35846EPSS 93% Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. Cockpit 0.11.2+ Fix from $2,3002020-12-30 CRITICAL 9.8 CVE-2020-35847EPSS 98% Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. Cockpit 0.11.2+ Fix from $2,3002020-12-30 CRITICAL 9.8 CVE-2020-35848EPSS 75% Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function. Cockpit 0.11.2+ Fix from $2,3002020-12-30 MEDIUM 6.1 CVE-2020-14408 An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of ar… Cockpit No fix yet Fix from $1,6002020-06-17 CRITICAL 9.8 CVE-2018-15540 Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended … Cockpit No fix yet Fix from $2,3002018-10-15 HIGH 8.8 CVE-2018-15539 Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc. Cockpit Mitigation only Fix from $1,9502018-10-15 MEDIUM 6.1 CVE-2018-15538 Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities. Cockpit No fix yet Fix from $1,6002018-10-15 CRITICAL 9.1 CVE-2017-14611 SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the ur… Cockpit No fix yet Fix from $2,3002018-04-10