Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 1.2% | — | CockpitAI | 28/3/2024 | 17/6/2026 | A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer. | |
| Analizada | Media (5.4) | 0.32% | — | Agentejo Cockpit | 29/2/2024 | 17/6/2026 | A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded. | |
| Modificada | Media (6.1) | 0.98% | 💥 PoC | Agentejo Cockpit | 8/9/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file. | |
| Modificada | Media (6.1) | 2.5% | 💥 Exploit | Agentejo Cockpit | 20/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | |
| Modificada | Media (5.4) | 0.56% | — | Agentejo Cockpit | 19/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | |
| Modificada | Media (6.1) | 0.61% | — | Agentejo Cockpit | 19/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | |
| Modificada | Media (4.8) | 0.64% | — | Agentejo Cockpit | 18/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. | |
| Modificada | Media (5.4) | 0.57% | — | Agentejo Cockpit | 17/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | |
| Modificada | Media (6.1) | 0.64% | — | Agentejo Cockpit | 14/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3. | |
| Modificada | Media (5.4) | 0.47% | — | Agentejo Cockpit | 6/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. | |
| Modificada | Alta (8.8) | 1.1% | — | Agentejo Cockpit | 6/8/2023 | 17/6/2026 | PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. | |
| Modificada | Alta (8.8) | 0.53% | — | Agentejo Cockpit | 20/7/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands. | |
| Modificada | Alta (7.5) | 0.88% | — | Agentejo Cockpit | 20/7/2023 | 17/6/2026 | Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data. | |
| Modificada | Media (4.6) | 0.30% | — | It-novum Openitcockpit | 6/7/2023 | 17/6/2026 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6. | |
| Modificada | Alta (8.8) | 0.71% | — | It-novum Openitcockpit | 25/6/2023 | 17/6/2026 | it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface. | |
| Modificada | Media (4.4) | 0.47% | — | It-novum Openitcockpit | 13/6/2023 | 17/6/2026 | Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5. | |
| Modificada | Alta (8.8) | 0.99% | — | Agentejo Cockpit | 10/3/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1. | |
| Modificada | Media (5.5) | 0.35% | — | Agentejo Cockpit | 3/3/2023 | 17/6/2026 | Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0. | |
| Modificada | Media (6.1) | 0.71% | — | Agentejo Cockpit | 21/2/2023 | 17/6/2026 | Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue. | |
| Modificada | Media (5.4) | 0.37% | — | Agentejo Cockpit | 11/2/2023 | 17/6/2026 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev. | |
| Modificada | Alta (8.8) | 0.34% | — | Agentejo Cockpit | 9/2/2023 | 17/6/2026 | Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8. | |
| Modificada | Alta (8.8) | 1.7% | — | Agentejo Cockpit | 15/8/2022 | 17/6/2026 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2. | |
| Modificada | Crítica (9.8) | 1.3% | — | Agentejo Cockpit | 8/8/2022 | 17/6/2026 | Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0. | |
| Modificada | Alta (7.5) | 0.68% | — | Cockpit-project CockpitRedhat Enterprise Linux | 10/3/2022 | 17/6/2026 | A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate… | |
| Modificada | Media (4.3) | 1.3% | — | Cockpit-project CockpitRedhat Enterprise Linux | 10/3/2022 | 17/6/2026 | Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks. |