Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2024-29020
JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive informa…
Jumpserver
3.10.6+
MEDIUM 5.3
CVE-2024-29024
JumpServer is an open source bastion host and an operation and maintenance security audit system.
An authenticated user can exploit the Insecure Dire…
Jumpserver
3.10.6+
CRITICAL 9.8
CVE-2024-2352
A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDe…
1panel
1.10.2-lts+
MEDIUM 6.1
CVE-2024-24763
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this…
Jumpserver
3.10.0+
HIGH 7.5
CVE-2024-24768
1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure…
1panel
Patch available
HIGH 7.8
CVE-2023-50612
Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive …
Cloudexplorer Lite
No fix yet
CRITICAL 9.8
CVE-2023-48193
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering…
Jumpserver
Mitigation only
MEDIUM 5.3
CVE-2023-46138
JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior to version 3.8.0, the def…
Jumpserver
3.8.0+
CRITICAL 9.8
CVE-2023-44397
CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a …
Cloudexplorer Lite
1.4.1+
MEDIUM 5.3
CVE-2023-46123
jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications. A fl…
Jumpserver
3.8.0+
CRITICAL 9.9
CVE-2023-43651
JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leadi…
Jumpserver
2.28.20 / 3.7.1+
CRITICAL 9.8
CVE-2023-42818
JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the cor…
Jumpserver
3.5.6 / 3.6.5+
CRITICAL 9.1
CVE-2023-43652
JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH publ…
Jumpserver
2.28.20 / 3.7.1+
HIGH 7.4
CVE-2023-43650
JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-force attacks due to the absenc…
Jumpserver
2.28.20 / 3.7.1+
HIGH 8.8
CVE-2023-42819
JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system. A user can use the 'Job-Temp…
Jumpserver
3.6.5+
HIGH 8.2
CVE-2023-42820EPSS 5%
JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly…
Jumpserver
2.28.19 / 3.6.5+
HIGH 7.5
CVE-2023-42147
An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.
Cloudexplorer Lite
No fix yet
MEDIUM 5.3
CVE-2023-42442EPSS 56%
JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to …
Jumpserver
3.5.5 / 3.6.4+
CRITICAL 9.8
CVE-2023-42405
SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService.list(), …
Rackshift
No fix yet
CRITICAL 9.8
CVE-2023-39966
1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead …
1panel
No fix yet
HIGH 7.5
CVE-2023-39964
1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads allow an attacker to read ar…
1panel
No fix yet
CRITICAL 9.8
CVE-2023-38692
CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the…
Cloudexplorer Lite
1.3.1+
HIGH 8.8
CVE-2023-37917
KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can become admin by editing the `isadm…
Kubepi
1.6.5+
HIGH 7.5
CVE-2023-37916
KubePi is an opensource kubernetes management panel. The endpoint /kubepi/api/v1/users/search?pageNum=1&&pageSize=10 leak password hash of any user (…
Kubepi
1.6.5+
HIGH 8.8
CVE-2023-37477EPSS 6%
1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall fun…
1panel
1.4.3+
HIGH 8.8
CVE-2023-36457
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malic…
1panel
1.3.6+
HIGH 8.8
CVE-2023-36458
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malic…
1panel
1.3.6+
CRITICAL 9.8
CVE-2023-34240
Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This …
Cloudexplorer Lite
1.2.0+
HIGH 8.8
CVE-2023-3423
Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.
Cloudexplorer Lite
1.2.0+
MEDIUM 5.4
CVE-2022-42225
Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute an…
Lina
after 2.26.0