← Back

Agentejo

agentejo

31 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Cockpit
cockpit

CVEs (31)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Agentejo
1Cockpit
Jun 17, 2026
Aug 15, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
1Agentejo
1Cockpit
Jun 17, 2026
Aug 8, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
1Agentejo
1Cockpit
Jun 17, 2026
Jan 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check...Show more
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.Show less
1Agentejo
1Cockpit
Jun 17, 2026
Dec 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
1Agentejo
1Cockpit
Jun 17, 2026
Dec 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
1Agentejo
1Cockpit
Jun 17, 2026
Dec 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
1Agentejo
1Cockpit
Jun 17, 2026
Jun 17, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected...Show more
An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.Show less
1Agentejo
1Cockpit
Nov 21, 2024
Oct 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Trave...Show more
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.Show less
1Agentejo
1Cockpit
Nov 21, 2024
Oct 15, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.
1Agentejo
1Cockpit
Nov 21, 2024
Oct 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.
1Agentejo
1Cockpit
Nov 21, 2024
Apr 10, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_conte...Show more
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.Show less