Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
openitcockpit vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2020-10791
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT prior to 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
It-novum Openitcockpit
7.5
CVSSv3
CVE-2020-10792
openITCOCKPIT up to and including 3.7.2 allows remote malicious users to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
It-novum Openitcockpit
4.6
CVSSv3
CVE-2023-3520
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit before 4.6.6.
It-novum Openitcockpit
8.8
CVSSv3
CVE-2023-36663
it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 prior to 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.
It-novum Openitcockpit 4.6.4
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-35977
CVE-2023-49335
man-in-the-middle
CVE-2024-4947
CVE-2024-31714
memory leak
SQL
CVE-2024-35994
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2