Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cockpit MEDIUM 6.5
CVE-2026-31891

Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially af…

Fix: 2.13.5+
Fix from $1,600 2026-03-18
Cockpit MEDIUM 6.1
CVE-2025-7053

A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/u…

Fix: after 2.11.3
Fix from $1,600 2025-07-04
Cockpit CRITICAL 9.8
CVE-2024-4825

A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post reque…

Mitigation only
Fix from $2,300 2024-05-14
Cockpit MEDIUM 5.4
CVE-2024-2001

A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infect…

Mitigation only
Fix from $1,600 2024-02-29
Cockpit MEDIUM 6.1
CVE-2023-41564

An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a …

Mitigation only
Fix from $1,600 2023-09-08
Cockpit MEDIUM 6.1
CVE-2023-4451

Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

Fix: after 2.6.3
Fix from $1,600 2023-08-20
Cockpit MEDIUM 6.1
CVE-2023-4432

Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

Fix: after 2.6.3
Fix from $1,600 2023-08-19
Cockpit MEDIUM 5.4
CVE-2023-4433

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

Fix: after 2.6.3
Fix from $1,600 2023-08-19
Cockpit MEDIUM 5.4
CVE-2023-4395

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

Fix: 2.6.4+
Fix from $1,600 2023-08-17
Cockpit MEDIUM 6.1
CVE-2023-4321

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.

Fix: 2.4.3+
Fix from $1,600 2023-08-14
Cockpit HIGH 8.8
CVE-2023-4195

PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

Fix: 2.6.3+
Fix from $1,950 2023-08-06
Cockpit MEDIUM 5.4
CVE-2023-4196

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

Fix: 2.6.3+
Fix from $1,600 2023-08-06
Cockpit HIGH 8.8
CVE-2023-37650

A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.

Fix: after 2.5.2
Fix from $1,950 2023-07-20
Cockpit HIGH 7.5
CVE-2023-37649

Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.

Fix: after 2.5.2
Fix from $1,950 2023-07-20
Cockpit HIGH 8.8
CVE-2023-1313

Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.

Fix: after 2.4.0
Fix from $1,950 2023-03-10
Cockpit MEDIUM 5.5
CVE-2023-1160

Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.

Fix: after 2.3.9
Fix from $1,600 2023-03-03
Cockpit MEDIUM 6.1
CVE-2021-32857

Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML s…

Fix: after 0.12.2
Fix from $1,600 2023-02-21
Cockpit MEDIUM 5.4
CVE-2023-0780

Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.

Fix: 2.3.9+
Fix from $1,600 2023-02-11
Cockpit HIGH 8.8
CVE-2023-0759

Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.

Fix: 2.3.8+
Fix from $1,950 2023-02-09
Cockpit HIGH 8.8
CVE-2022-2818

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

Fix: 2.2.2+
Fix from $1,950 2022-08-15
Cockpit CRITICAL 9.8
CVE-2022-2713

Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.

Fix: 2.2.0+
Fix from $2,300 2022-08-08
Cockpit CRITICAL 9.8
CVE-2020-35131EPSS 51%

Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/…

Fix: 0.6.1+
Fix from $2,300 2021-01-08
Cockpit CRITICAL 9.8
CVE-2020-35846EPSS 93%

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.

Fix: 0.11.2+
Fix from $2,300 2020-12-30
Cockpit CRITICAL 9.8
CVE-2020-35847EPSS 98%

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

Fix: 0.11.2+
Fix from $2,300 2020-12-30
Cockpit CRITICAL 9.8
CVE-2020-35848EPSS 75%

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.

Fix: 0.11.2+
Fix from $2,300 2020-12-30
Cockpit MEDIUM 6.1
CVE-2020-14408

An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of ar…

No fix yet
Fix from $1,600 2020-06-17
Cockpit CRITICAL 9.8
CVE-2018-15540

Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended …

No fix yet
Fix from $2,300 2018-10-15
Cockpit HIGH 8.8
CVE-2018-15539

Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.

Mitigation only
Fix from $1,950 2018-10-15
Cockpit MEDIUM 6.1
CVE-2018-15538

Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.

No fix yet
Fix from $1,600 2018-10-15
Cockpit CRITICAL 9.1
CVE-2017-14611

SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the ur…

No fix yet
Fix from $2,300 2018-04-10