Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openitcockpit HIGH 8.8
CVE-2026-24893

openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contai…

Fix: 5.5.2+
Fix from $1,950 2026-04-14
Openitcockpit HIGH 8.8
CVE-2026-24892

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Ed…

Fix: 5.4.0+
Fix from $1,950 2026-02-20
Openitcockpit HIGH 7.5
CVE-2026-24891

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below c…

Fix: 5.4.0+
Fix from $1,950 2026-02-20
Openitcockpit HIGH 8.8
CVE-2023-36663

it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API inter…

Patch available
Fix from $1,950 2023-06-25
Openitcockpit CRITICAL 9.1
CVE-2020-10788

openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connection…

Fix: 3.7.3+
Fix from $2,300 2020-03-25
Openitcockpit CRITICAL 9.8
CVE-2020-10789

openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandl…

Fix: 3.7.3+
Fix from $2,300 2020-03-25
Openitcockpit MEDIUM 6.5
CVE-2020-10791

app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger out…

Fix: 3.7.3+
Fix from $1,600 2020-03-25
Openitcockpit MEDIUM 5.4
CVE-2020-10790

openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.

Fix: 3.7.3+
Fix from $1,600 2020-03-25
Openitcockpit HIGH 7.5
CVE-2020-10792

openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev"…

Fix: after 3.7.2
Fix from $1,950 2020-03-20
Openitcockpit MEDIUM 6.1
CVE-2019-10227

openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.

Fix: 3.7.1+
Fix from $1,600 2019-12-31
Openitcockpit CRITICAL 9.8
CVE-2019-15490

openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.

Fix: 3.7.1+
Fix from $2,300 2019-08-23
Openitcockpit CRITICAL 9.8
CVE-2019-15494

openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.

Fix: 3.7.1+
Fix from $2,300 2019-08-23
Openitcockpit HIGH 8.8
CVE-2019-15491

openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.

Fix: 3.7.1+
Fix from $1,950 2019-08-23
Openitcockpit HIGH 7.5
CVE-2019-15493

openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.

Fix: 3.7.1+
Fix from $1,950 2019-08-23
Openitcockpit MEDIUM 6.1
CVE-2019-15492

openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.

Fix: 3.7.1+
Fix from $1,600 2019-08-23