Skip to main content

Vendor archive

fit2cloud CVEs

Beta · best-effort

77 CVEs tagged to vendor fit2cloud14 Critical, 31 High, 27 Medium, 5 Low, 0 Unrated.

CVE-2026-42463

Published May 13, 2026

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and A…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33324

Published May 5, 2026

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. T…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32950

Published Mar 20, 2026

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasourc…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-32949

Published Mar 20, 2026

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-32622

Published Mar 19, 2026

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaw…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-31864

Published Mar 13, 2026

JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template Injection (SSTI) vulnerability exists in JumpServer's Appl…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-31798

Published Mar 13, 2026

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly validates certificates in the Custom…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-15598

Published Mar 3, 2026

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token…

CVSS 2.9 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15597

Published Mar 2, 2026

A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Suc…

CVSS 2.1 · Low
evidence mentions
17
Buzz score
39.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-70981

Published Feb 12, 2026

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-69285

Published Jan 21, 2026

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerability in the /api/v1/datasourc…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2026-23525

Published Jan 18, 2026

1Panel is an open-source, web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) vulnerability exists in the 1Panel App Store when viewing applic…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-34430

Published Dec 10, 2025

1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name management functionality. The affected endpoint does not impleme…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-34429

Published Dec 10, 2025

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality. The port-change endpoint lacks CSRF defense…

CVSS 7.0 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-34410

Published Dec 10, 2025

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the settings panel (/settings/panel)…

CVSS 7.0 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-66508

Published Dec 9, 2025

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.14 and below use Gin's default configuration which trusts all IP addresses as proxies (…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66507

Published Dec 9, 2025

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14117

Published Dec 6, 2025

A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The attack may be initiated remote…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-58044

Published Dec 1, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62795

Published Oct 30, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privileged authenticated user can i…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62712

Published Oct 30, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated,…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-56413

Published Sep 10, 2025

OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /api/v2/hosts/ssh/ope…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54424

Published Aug 1, 2025

1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below, the HTTPS protocol used for…

CVSS 8.1 · High
Buzz score
5.2
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-27095

Published Mar 31, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.10.18, an attacker with a low-privileged account can access…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40629

Published Jul 18, 2024

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and Remot…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 77 CVEsPage 1 of 4