It-novum
It-novum Openitcockpit: vulnerabilidades y CVE
It-novum Openitcockpit tiene 17 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses3
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-24893 | Alta (8.8) | 1.4% | — | 14 abr 2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user… |
| CVE-2026-24892 | Alta (8.8) | 0.83% | — | 20 feb 2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern… |
| CVE-2026-24891 | Alta (7.5) | 0.36% | — | 20 feb 2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker… |
| CVE-2023-3520 | Media (4.6) | 0.30% | — | 6 jul 2023 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6. |
| CVE-2023-36663 | Alta (8.8) | 0.71% | — | 25 jun 2023 | it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface. |
| CVE-2023-3218 | Media (4.4) | 0.47% | — | 13 jun 2023 | Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5. |
| CVE-2020-10788 | Crítica (9.1) | 1.6% | — | 25 mar 2020 | openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections. |
| CVE-2020-10791 | Media (6.5) | 1.2% | — | 25 mar 2020 | app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka… |
| CVE-2020-10790 | Media (5.4) | 0.91% | — | 25 mar 2020 | openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS. |
| CVE-2020-10789 | Crítica (9.8) | 2.0% | — | 25 mar 2020 | openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php. |
| CVE-2020-10792 | Alta (7.5) | 1.9% | — | 20 mar 2020 | openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header. |
| CVE-2019-10227 | Media (6.1) | 1.2% | — | 31 dic 2019 | openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. |
| CVE-2019-15494 | Crítica (9.8) | 1.5% | — | 23 ago 2019 | openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. |
| CVE-2019-15493 | Alta (7.5) | 1.2% | — | 23 ago 2019 | openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21. |
| CVE-2019-15492 | Media (6.1) | 0.82% | — | 23 ago 2019 | openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. |
| CVE-2019-15491 | Alta (8.8) | 0.60% | — | 23 ago 2019 | openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. |
| CVE-2019-15490 | Crítica (9.8) | 1.7% | — | 23 ago 2019 | openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.