Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.4% | — | It-novum Openitcockpit | 14/4/2026 | 25/7/2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the monitoring backend.… | |
| Analizada | Alta (8.8) | 0.83% | — | It-novum Openitcockpit | 20/2/2026 | 17/6/2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized changelog data derived from attacker-influenced… | |
| Analizada | Alta (7.5) | 0.36% | — | It-novum Openitcockpit | 20/2/2026 | 17/6/2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls PHP's unserialize() on job payloads… | |
| Modificada | Media (4.6) | 0.30% | — | It-novum Openitcockpit | 6/7/2023 | 17/6/2026 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6. | |
| Modificada | Alta (8.8) | 0.71% | — | It-novum Openitcockpit | 25/6/2023 | 17/6/2026 | it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface. | |
| Modificada | Media (4.4) | 0.47% | — | It-novum Openitcockpit | 13/6/2023 | 17/6/2026 | Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5. | |
| Modificada | Crítica (9.1) | 1.6% | — | It-novum Openitcockpit | 25/3/2020 | 17/6/2026 | openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections. | |
| Modificada | Media (6.5) | 1.2% | — | It-novum Openitcockpit | 25/3/2020 | 17/6/2026 | app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module. | |
| Modificada | Media (5.4) | 0.91% | — | It-novum Openitcockpit | 25/3/2020 | 17/6/2026 | openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS. | |
| Modificada | Crítica (9.8) | 2.0% | — | It-novum Openitcockpit | 25/3/2020 | 17/6/2026 | openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php. | |
| Modificada | Alta (7.5) | 1.9% | — | It-novum Openitcockpit | 20/3/2020 | 17/6/2026 | openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header. | |
| Modificada | Media (6.1) | 1.2% | — | It-novum Openitcockpit | 31/12/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. | |
| Modificada | Crítica (9.8) | 1.5% | — | It-novum Openitcockpit | 23/8/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. | |
| Modificada | Alta (7.5) | 1.2% | — | It-novum Openitcockpit | 23/8/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21. | |
| Modificada | Media (6.1) | 0.82% | — | It-novum Openitcockpit | 23/8/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. | |
| Modificada | Alta (8.8) | 0.60% | — | It-novum Openitcockpit | 23/8/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. | |
| Modificada | Crítica (9.8) | 1.7% | — | It-novum Openitcockpit | 23/8/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21. |