Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

106 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.58%—Agentejo Cockpit15/10/201817/6/2026
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.
ModificadaMedia (6.1)0.84%—Agentejo Cockpit15/10/201817/6/2026
Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.
ModificadaMedia (5.4)0.55%—Getcockpit Cockpit25/5/201817/6/2026
Cockpit 0.5.5 has XSS via a collection, form, or region.
ModificadaCrítica (9.1)8.5%💥 ExploitGetcockpit Cockpit2/5/201817/6/2026
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which…
ModificadaCrítica (9.1)1.9%—Agentejo Cockpit10/4/201817/6/2026
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
ModificadaAlta (9.3)1.4%—Jetroplatforms Jetro Cockpit Secure Browsing18/2/201417/6/2026
The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary programs by providing a .EXE extension.
Orbitaley — Vulnerabilidades