📦 Cockpit

by Agentejo

🔍 What is Cockpit?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-2818

CRITICAL CVSS 9.8 Aug 15, 2022

CVE-2022-2818 is an improper removal of sensitive information vulnerability in the cockpit repository that could expose sensitive data like credentials or tokens. This affects users of cockpit version...

CVE-2020-35846

CRITICAL CVSS 9.8 Dec 30, 2020

CVE-2020-35846 is a NoSQL injection vulnerability in Agentejo Cockpit CMS that allows attackers to execute arbitrary commands on affected systems. The vulnerability exists in the authentication contro...

CVE-2020-35848

CRITICAL CVSS 9.8 Dec 30, 2020

CVE-2020-35848 is a NoSQL injection vulnerability in Agentejo Cockpit CMS that allows attackers to execute arbitrary database queries via the password reset function. This affects all Cockpit installa...

CVE-2023-37649

HIGH CVSS 7.5 Jul 20, 2023

This vulnerability allows unauthorized attackers to access sensitive data through incorrect access control in Cockpit CMS's Content component. It affects all users running Cockpit CMS v2.5.2 or earlie...

CVE-2023-1313

HIGH CVSS 8.8 Mar 10, 2023

This vulnerability allows attackers to upload malicious files to the Cockpit CMS due to insufficient file type validation. It affects all users running Cockpit versions prior to 2.4.1, potentially lea...