Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

106 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)50%💥 ExploitAgentejo Cockpit8/1/202117/6/2026
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
ModificadaMedia (6.5)1.7%—Cockpit-project Cockpit30/12/202017/6/2026
An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.
ModificadaCrítica (9.8)75%💥 ExploitAgentejo Cockpit30/12/202017/6/2026
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
ModificadaCrítica (9.8)98%💥 ExploitAgentejo Cockpit30/12/202017/6/2026
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
ModificadaCrítica (9.8)93%💥 ExploitAgentejo Cockpit30/12/202017/6/2026
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
ModificadaMedia (6.1)3.0%💥 ExploitAgentejo Cockpit17/6/202017/6/2026
An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.
ModificadaAlta (8)0.52%—SAP Adaptive Server Enterprise Cockpit12/5/202017/6/2026
Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local network, to get sensitive and confidential information, leading to Information Disclosure. It can be used to get user account credentials, tamper with system data and impact system availability.
ModificadaCrítica (9.1)1.6%—It-novum Openitcockpit25/3/202017/6/2026
openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.
ModificadaMedia (6.5)1.2%—It-novum Openitcockpit25/3/202017/6/2026
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
ModificadaMedia (5.4)0.91%—It-novum Openitcockpit25/3/202017/6/2026
openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
ModificadaCrítica (9.8)2.0%—It-novum Openitcockpit25/3/202017/6/2026
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.
ModificadaAlta (7.5)1.9%—It-novum Openitcockpit20/3/202017/6/2026
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
ModificadaAlta (7.8)1.9%—Wago E!cockpit11/3/202017/6/2026
An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write arbitrary files to arbitrary locations on WAGO controllers as a part of executing a firmware update,…
ModificadaAlta (7.8)1.1%—Wago E!cockpit11/3/202017/6/2026
An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation software v1.6.1.5. A specially crafted firmware update file can allow an attacker to install an older firmware version while the user thinks a newer firmware version is being installed.…
ModificadaAlta (7.5)1.1%—Wago E!cockpit11/3/202017/6/2026
A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily intercept, interpret, and manipulate data coming from, or destined for e!Cockpit. This includes passwords, configurations, and binaries being…
ModificadaMedia (5.5)0.34%—Wago E!cockpit11/3/202017/6/2026
A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.
ModificadaMedia (6.1)1.2%💥 ExploitIt-novum Openitcockpit31/12/201917/6/2026
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
ModificadaCrítica (9.8)1.5%—It-novum Openitcockpit23/8/201917/6/2026
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
ModificadaAlta (7.5)1.2%—It-novum Openitcockpit23/8/201917/6/2026
openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.
ModificadaMedia (6.1)0.82%—It-novum Openitcockpit23/8/201917/6/2026
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
ModificadaAlta (8.8)0.60%—It-novum Openitcockpit23/8/201917/6/2026
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
ModificadaCrítica (9.8)1.7%—It-novum Openitcockpit23/8/201917/6/2026
openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.
ModificadaAlta (7.8)0.24%—Cockpit-ovirt17/5/201917/6/2026
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain-text. At the of the deployment procedure, these files are deleted.
ModificadaAlta (7.5)4.9%—Cockpit-project CockpitFedoraproject FedoraRedhat Virtualization26/3/201917/6/2026
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.
ModificadaCrítica (9.8)2.3%—Agentejo Cockpit15/10/201817/6/2026
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.
Orbitaley — Vulnerabilidades