Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
it-novum vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2019-15490
openITCOCKPIT prior to 3.7.1 allows code injection, aka RVID 1-445b21.
It-novum Openitcockpit
8.8
CVSSv3
CVE-2019-15491
openITCOCKPIT prior to 3.7.1 has CSRF, aka RVID 2-445b21.
It-novum Openitcockpit
6.1
CVSSv3
CVE-2019-15492
openITCOCKPIT prior to 3.7.1 has reflected XSS, aka RVID 3-445b21.
It-novum Openitcockpit
7.5
CVSSv3
CVE-2019-15493
openITCOCKPIT prior to 3.7.1 allows deletion of files, aka RVID 4-445b21.
It-novum Openitcockpit
9.8
CVSSv3
CVE-2019-15494
openITCOCKPIT prior to 3.7.1 allows SSRF, aka RVID 5-445b21.
It-novum Openitcockpit
4.4
CVSSv3
CVE-2023-3218
Race Condition within a Thread in GitHub repository it-novum/openitcockpit before 4.6.5.
It-novum Openitcockpit
6.5
CVSSv3
CVE-2020-10791
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT prior to 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
It-novum Openitcockpit
5.4
CVSSv3
CVE-2020-10790
openITCOCKPIT prior to 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
It-novum Openitcockpit
4.6
CVSSv3
CVE-2023-3520
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit before 4.6.6.
It-novum Openitcockpit
6.1
CVSSv3
CVE-2019-10227
openITCOCKPIT prior to 3.7.1 has reflected XSS in the 404-not-found component.
It-novum Openitcockpit
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4040
cross-site scripting
CVE-2023-25790
CVE-2024-2961
XML external entity
CVE-2024-26926
CVE-2024-32806
CVE-2024-32711
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »