it-novum
Enterprise Softwarecommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting it-novum.
- CVE-2026-24893openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion8.8
- CVE-2026-24892openITCOCKPIT has Unsafe Deserialization in openITCOCKPIT Changelog Handling7.5
- CVE-2026-24891openITCOCKPIT has Unsafe PHP Deserialization in Gearman Worker Allowing Conditional Object Injection7.5
- CVE-2023-3520Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in it-novum/openitcockpit4.6
- CVE-2023-36663it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.8.8
- CVE-2023-3218Race Condition within a Thread in it-novum/openitcockpit4.4
- CVE-2020-10788openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.9.1
- CVE-2020-10789openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageI...9.8
- CVE-2020-10790openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.5.4
- CVE-2020-10791app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Conne...6.5
- CVE-2020-10792openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.7.5
- CVE-2019-10227openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.6.1
- CVE-2019-15494openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.9.8
- CVE-2019-15493openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.7.5
- CVE-2019-15492openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.6.1