Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

106 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.3)1.2%—CockpitAI28/3/202417/6/2026
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
AnalizadaMedia (5.4)0.32%—Agentejo Cockpit29/2/202417/6/2026
A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.
ModificadaMedia (6.1)0.98%💥 PoCAgentejo Cockpit8/9/202317/6/2026
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.
ModificadaMedia (6.1)2.5%💥 ExploitAgentejo Cockpit20/8/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
ModificadaMedia (5.4)0.56%—Agentejo Cockpit19/8/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
ModificadaMedia (6.1)0.61%—Agentejo Cockpit19/8/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
ModificadaMedia (4.8)0.64%—Agentejo Cockpit18/8/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
ModificadaMedia (5.4)0.57%—Agentejo Cockpit17/8/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
ModificadaMedia (6.1)0.64%—Agentejo Cockpit14/8/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.
ModificadaMedia (5.4)0.47%—Agentejo Cockpit6/8/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
ModificadaAlta (8.8)1.1%—Agentejo Cockpit6/8/202317/6/2026
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
ModificadaAlta (8.8)0.53%—Agentejo Cockpit20/7/202317/6/2026
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
ModificadaAlta (7.5)0.88%—Agentejo Cockpit20/7/202317/6/2026
Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.
ModificadaMedia (4.6)0.30%—It-novum Openitcockpit6/7/202317/6/2026
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
ModificadaAlta (8.8)0.71%—It-novum Openitcockpit25/6/202317/6/2026
it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.
ModificadaMedia (4.4)0.47%—It-novum Openitcockpit13/6/202317/6/2026
Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.
ModificadaAlta (8.8)0.99%—Agentejo Cockpit10/3/202317/6/2026
Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.
ModificadaMedia (5.5)0.35%—Agentejo Cockpit3/3/202317/6/2026
Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.
ModificadaMedia (6.1)0.71%—Agentejo Cockpit21/2/202317/6/2026
Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
ModificadaMedia (5.4)0.37%—Agentejo Cockpit11/2/202317/6/2026
Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.
ModificadaAlta (8.8)0.34%—Agentejo Cockpit9/2/202317/6/2026
Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
ModificadaAlta (8.8)1.7%—Agentejo Cockpit15/8/202217/6/2026
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
ModificadaCrítica (9.8)1.3%—Agentejo Cockpit8/8/202217/6/2026
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
ModificadaAlta (7.5)0.68%—Cockpit-project CockpitRedhat Enterprise Linux10/3/202217/6/2026
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate…
ModificadaMedia (4.3)1.3%—Cockpit-project CockpitRedhat Enterprise Linux10/3/202217/6/2026
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Orbitaley — Vulnerabilidades