Home/Product/it novum openitcockpit
Product

it novum openitcockpit

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-24893
< 5.5.2
openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to v
8.8HIGH
CVE-2026-24892
< 5.4.0
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITC
7.5HIGH
CVE-2026-24891
< 5.4.0
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Version
7.5HIGH
CVE-2023-3520
< 4.6.6
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
4.6MEDIUM
CVE-2023-36663
all versions
it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort paramet
8.8HIGH
CVE-2023-3218
< 4.6.5
Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.
4.4MEDIUM
CVE-2020-10788
< 3.7.3
openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for W
9.1CRITICAL
CVE-2020-10791
< 3.7.3
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated u
6.5MEDIUM
CVE-2020-10790
< 3.7.3
openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
5.4MEDIUM
CVE-2020-10789
< 3.7.3
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacter
9.8CRITICAL
CVE-2020-10792
<= 3.7.2
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostna
7.5HIGH
CVE-2019-10227
< 3.7.1
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
6.1MEDIUM
CVE-2019-15494
< 3.7.1
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
9.8CRITICAL
CVE-2019-15493
< 3.7.1
openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.
7.5HIGH
CVE-2019-15492
< 3.7.1
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
6.1MEDIUM
CVE-2019-15491
< 3.7.1
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
8.8HIGH
CVE-2019-15490
< 3.7.1
openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin