Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cockpit CRITICAL 9.8
CVE-2024-4825

A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post reque…

Mitigation only
Fix from $2,300 2024-05-14
Cockpit MEDIUM 5.4
CVE-2024-2001

A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infect…

Mitigation only
Fix from $1,600 2024-02-29
Cockpit MEDIUM 6.1
CVE-2023-41564

An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a …

Mitigation only
Fix from $1,600 2023-09-08
Cockpit MEDIUM 6.1
CVE-2020-14408

An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of ar…

No fix yet
Fix from $1,600 2020-06-17
Cockpit CRITICAL 9.8
CVE-2018-15540

Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended …

No fix yet
Fix from $2,300 2018-10-15
Cockpit HIGH 8.8
CVE-2018-15539

Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.

Mitigation only
Fix from $1,950 2018-10-15
Cockpit MEDIUM 6.1
CVE-2018-15538

Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.

No fix yet
Fix from $1,600 2018-10-15
Cockpit CRITICAL 9.1
CVE-2017-14611

SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the ur…

No fix yet
Fix from $2,300 2018-04-10