Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.9
CVE-2021-45081
An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.
Cobbler
after 3.3.1
CRITICAL 9.8
CVE-2021-40323EPSS 88%
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
Cobbler
after 3.3.0
HIGH 7.5
CVE-2021-40324EPSS 69%
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
Cobbler
after 3.3.0
HIGH 7.5
CVE-2021-40325
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
Cobbler
after 3.3.0
MEDIUM 6.1
CVE-2016-9605
A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary…
Cobbler
Mitigation only
CRITICAL 9.8
CVE-2017-1000469EPSS 6%
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as r…
Cobbler
after 2.8.2
MEDIUM 6.8
CVE-2011-4953
The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related …
Cobbler
after 2.2.1