Vulnerabilities (CVE)

Filtered by vendor Agentejo Subscribe
Filtered by product Cockpit
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-4195 1 Agentejo 1 Cockpit 2023-08-10 N/A 8.8 HIGH
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
CVE-2022-2818 1 Agentejo 1 Cockpit 2023-08-02 N/A 8.8 HIGH
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
CVE-2023-37650 1 Agentejo 1 Cockpit 2023-07-26 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
CVE-2023-37649 1 Agentejo 1 Cockpit 2023-07-26 N/A 7.5 HIGH
Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.
CVE-2018-15539 1 Agentejo 1 Cockpit 2018-11-30 6.8 MEDIUM 8.8 HIGH
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.