« Volver al listado

It-novum

It-novum Openitcockpit: vulnerabilidades y CVE

It-novum Openitcockpit tiene 17 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE17
Últimos 12 meses3
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-24893Alta (8.8)1.4%—14 abr 2026
openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user…
CVE-2026-24892Alta (8.8)0.83%—20 feb 2026
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern…
CVE-2026-24891Alta (7.5)0.36%—20 feb 2026
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker…
CVE-2023-3520Media (4.6)0.30%—6 jul 2023
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
CVE-2023-36663Alta (8.8)0.71%—25 jun 2023
it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.
CVE-2023-3218Media (4.4)0.47%—13 jun 2023
Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.
CVE-2020-10788Crítica (9.1)1.6%—25 mar 2020
openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.
CVE-2020-10791Media (6.5)1.2%—25 mar 2020
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka…
CVE-2020-10790Media (5.4)0.91%—25 mar 2020
openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
CVE-2020-10789Crítica (9.8)2.0%—25 mar 2020
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.
CVE-2020-10792Alta (7.5)1.9%—20 mar 2020
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
CVE-2019-10227Media (6.1)1.2%—31 dic 2019
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
CVE-2019-15494Crítica (9.8)1.5%—23 ago 2019
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
CVE-2019-15493Alta (7.5)1.2%—23 ago 2019
openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.
CVE-2019-15492Media (6.1)0.82%—23 ago 2019
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
CVE-2019-15491Alta (8.8)0.60%—23 ago 2019
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
CVE-2019-15490Crítica (9.8)1.7%—23 ago 2019
openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter3
  2. T1210 Exploitation of Remote Services3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.