Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.54% | — | CockpitAI | 29/4/2026 | 17/6/2026 | Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filename bypasses an extension filter. This allows an authenticated attacker to rename arbitrary files with the .php file extension enabling arbitrary code to be executed on… | |
| Aplazada | Crítica (9.8) | 0.73% | — | CockpitAI | 29/4/2026 | 17/6/2026 | Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator. | |
| Aplazada | Baja (2.1) | 0.39% | — | Cockpit-hq CockpitAI | 20/4/2026 | 17/6/2026 | A vulnerability was detected in Cockpit-HQ Cockpit up to 2.13.5. Affected by this issue is some unknown functionality of the component Asset Handler/Aggregate Handler. The manipulation results in improper neutralization of special elements in data query logic. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Alta (8.8) | 1.4% | — | It-novum Openitcockpit | 14/4/2026 | 25/7/2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the monitoring backend.… | |
| Analizada | Media (4.3) | 0.35% | — | SAP Hana CockpitSAP Hana Database Explorer | 14/4/2026 | 17/6/2026 | Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer | |
| Pendiente de análisis | Crítica (9.8) | 9.2% | 💥 Exploit | CockpitAI | 7/4/2026 | 4/8/2026 | Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands,… | |
| Analizada | Media (6.5) | 0.39% | 💥 PoC | Agentejo Cockpit | 18/3/2026 | 17/6/2026 | Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the `/api/content/aggregate/{model}` endpoint is publicly… | |
| Analizada | Alta (8.8) | 0.83% | — | It-novum Openitcockpit | 20/2/2026 | 17/6/2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized changelog data derived from attacker-influenced… | |
| Analizada | Alta (7.5) | 0.36% | — | It-novum Openitcockpit | 20/2/2026 | 17/6/2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls PHP's unserialize() on job payloads… | |
| Aplazada | Alta (8.5) | 0.15% | — | Devolo Dlan CockpitAI | 8/1/2026 | 17/6/2026 | devolo dLAN Cockpit 4.3.1 contains an unquoted service path vulnerability in the 'DevoloNetworkService' that allows local non-privileged users to potentially execute arbitrary code. Attackers can exploit the insecure service path configuration by inserting malicious code in the system root path to execute with… | |
| Aplazada | Media (5.3) | 0.28% | 💥 PoC | G FFL CockpitAI | 6/12/2025 | 17/6/2026 | The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the server. | |
| Aplazada | Media (5.3) | 0.28% | 💥 PoC | G-ffl CockpitAI | 6/12/2025 | 17/6/2026 | The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the handle_enqueue_only() function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to delete arbitrary products. | |
| Aplazada | Media (6.1) | 0.43% | — | FunnelcockpitAI | 24/7/2025 | 17/6/2026 | The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (5.1) | 0.35% | — | Agentejo Cockpit | 4/7/2025 | 17/6/2026 | A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.11.4 is able to address… | |
| Aplazada | Alta (7.1) | 0.22% | — | FunnelcockpitAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit FunnelCockpit funnelcockpit allows Reflected XSS.This issue affects FunnelCockpit: from n/a through <= 1.4.3. | |
| Aplazada | Media (5.9) | 0.41% | — | FunnelcockpitAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit FunnelCockpit funnelcockpit allows Stored XSS.This issue affects FunnelCockpit: from n/a through <= 1.4.3. | |
| Aplazada | Alta (7.7) | 19% | 💥 Exploit | Cockpit-hq CockpitAI | 5/2/2025 | 17/6/2026 | Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter. | |
| Aplazada | Alta (8.4) | 0.49% | — | B&R Mapp CockpitAIB&R Mapp ViewAIB&R Mapp ServicesAIB&R Mapp MotionAI+1 | 2/12/2024 | 17/6/2026 | An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based… | |
| Aplazada | Crítica (9.3) | 0.17% | — | Himed Cockpit 12 PROAIHimed Cockpit 14 PRO PlusAIHimed Cockpit 18 PROAIHimed Cockpit 18 PRO PlusAI | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro (J31032-K2017-H260) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro+ (J31032-K2017-H436)… | |
| Modificada | Alta (8.8) | 0.44% | — | Tnbmobil Cockpit | 13/9/2024 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable. This issue affects Cockpit Software: before v2.13. | |
| Aplazada | Baja (3.2) | 0.28% | — | CockpitAILinux-pam PAM ENVAI | 3/7/2024 | 17/6/2026 | A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack. | |
| Modificada | Alta (7.5) | 0.39% | — | Tnbmobil Cockpit | 5/6/2024 | 17/6/2026 | Inclusion of Sensitive Information in Source Code vulnerability in TNB Mobile Solutions Cockpit Software allows Retrieve Embedded Sensitive Data. This issue affects Cockpit Software: before v0.251.1. | |
| Aplazada | Alta (7.2) | 0.17% | — | B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+21 | 14/5/2024 | 17/6/2026 | An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation… | |
| Analizada | Crítica (9.8) | 0.72% | — | Agentejo Cockpit | 14/5/2024 | 17/6/2026 | A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure. | |
| Aplazada | Alta (8.8) | 1.0% | — | CockpitAIOpensuse PCPAI | 28/3/2024 | 17/6/2026 | A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The… |