Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jumpserver MEDIUM 5.3
CVE-2024-29020

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive informa…

Fix: 3.10.6+
Fix from $1,600 2024-03-29
Jumpserver MEDIUM 5.3
CVE-2024-29024

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Dire…

Fix: 3.10.6+
Fix from $1,600 2024-03-29
1panel CRITICAL 9.8
CVE-2024-2352

A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDe…

Fix: 1.10.2-lts+
Fix from $2,300 2024-03-10
Jumpserver MEDIUM 6.1
CVE-2024-24763

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this…

Fix: 3.10.0+
Fix from $1,600 2024-02-20
1panel HIGH 7.5
CVE-2024-24768

1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure…

Patch available
Fix from $1,950 2024-02-05
Cloudexplorer Lite HIGH 7.8
CVE-2023-50612

Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive …

No fix yet
Fix from $1,950 2024-01-06
Jumpserver CRITICAL 9.8
CVE-2023-48193

Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering…

Mitigation only
Fix from $2,300 2023-11-28
Jumpserver MEDIUM 5.3
CVE-2023-46138

JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior to version 3.8.0, the def…

Fix: 3.8.0+
Fix from $1,600 2023-10-31
Cloudexplorer Lite CRITICAL 9.8
CVE-2023-44397

CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a …

Fix: 1.4.1+
Fix from $2,300 2023-10-30
Jumpserver MEDIUM 5.3
CVE-2023-46123

jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications. A fl…

Fix: 3.8.0+
Fix from $1,600 2023-10-25
Jumpserver CRITICAL 9.9
CVE-2023-43651

JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leadi…

Fix: 2.28.20 / 3.7.1+
Fix from $2,300 2023-09-27
Jumpserver CRITICAL 9.8
CVE-2023-42818

JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the cor…

Fix: 3.5.6 / 3.6.5+
Fix from $2,300 2023-09-27
Jumpserver CRITICAL 9.1
CVE-2023-43652

JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH publ…

Fix: 2.28.20 / 3.7.1+
Fix from $2,300 2023-09-27
Jumpserver HIGH 7.4
CVE-2023-43650

JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-force attacks due to the absenc…

Fix: 2.28.20 / 3.7.1+
Fix from $1,950 2023-09-27
Jumpserver HIGH 8.8
CVE-2023-42819

JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system. A user can use the 'Job-Temp…

Fix: 3.6.5+
Fix from $1,950 2023-09-27
Jumpserver HIGH 8.2
CVE-2023-42820EPSS 5%

JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly…

Fix: 2.28.19 / 3.6.5+
Fix from $1,950 2023-09-27
Cloudexplorer Lite HIGH 7.5
CVE-2023-42147

An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.

No fix yet
Fix from $1,950 2023-09-20
Jumpserver MEDIUM 5.3
CVE-2023-42442EPSS 56%

JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to …

Fix: 3.5.5 / 3.6.4+
Fix from $1,600 2023-09-15
Rackshift CRITICAL 9.8
CVE-2023-42405

SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService.list(), …

No fix yet
Fix from $2,300 2023-09-14
1panel CRITICAL 9.8
CVE-2023-39966

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead …

No fix yet
Fix from $2,300 2023-08-10
1panel HIGH 7.5
CVE-2023-39964

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads allow an attacker to read ar…

No fix yet
Fix from $1,950 2023-08-10
Cloudexplorer Lite CRITICAL 9.8
CVE-2023-38692

CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the…

Fix: 1.3.1+
Fix from $2,300 2023-08-04
Kubepi HIGH 8.8
CVE-2023-37917

KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can become admin by editing the `isadm…

Fix: 1.6.5+
Fix from $1,950 2023-07-21
Kubepi HIGH 7.5
CVE-2023-37916

KubePi is an opensource kubernetes management panel. The endpoint /kubepi/api/v1/users/search?pageNum=1&&pageSize=10 leak password hash of any user (…

Fix: 1.6.5+
Fix from $1,950 2023-07-21
1panel HIGH 8.8
CVE-2023-37477EPSS 6%

1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall fun…

Fix: 1.4.3+
Fix from $1,950 2023-07-18
1panel HIGH 8.8
CVE-2023-36457

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malic…

Fix: 1.3.6+
Fix from $1,950 2023-07-05
1panel HIGH 8.8
CVE-2023-36458

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malic…

Fix: 1.3.6+
Fix from $1,950 2023-07-05
Cloudexplorer Lite CRITICAL 9.8
CVE-2023-34240

Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This …

Fix: 1.2.0+
Fix from $2,300 2023-06-27
Cloudexplorer Lite HIGH 8.8
CVE-2023-3423

Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.

Fix: 1.2.0+
Fix from $1,950 2023-06-27
Lina MEDIUM 5.4
CVE-2022-42225

Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute an…

Fix: after 2.26.0
Fix from $1,600 2023-05-24