Skip to main content

Vendor/product archive

it-novum / openitcockpit CVEs

Beta · best-effort

17 CVEs tagged to it-novum / openitcockpit4 Critical, 7 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2026-24893

Published Apr 14, 2026

openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnera…

CVSS 8.8 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-24892

Published Feb 20, 2026

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contai…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-24891

Published Feb 20, 2026

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserializati…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-3520

Published Jul 6, 2023

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36663

Published Jun 25, 2023

it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10788

Published Mar 25, 2020

openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10791

Published Mar 25, 2020

app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF)…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10790

Published Mar 25, 2020

openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10789

Published Mar 25, 2020

openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in ap…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10792

Published Mar 20, 2020

openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1