Cockpit是Cockpit开源的一个交互式服务器管理界面。 Cockpit 2.4.1之前版本存在安全漏洞,该漏洞源于容易受到任意文件上传的攻击,导致攻击者可以绕过上传过滤器。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | cockpit-hq/cockpit | < 2.4.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | cockpit-hq/cockpit | 0 ~ 2.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extensions to bypass the upload filter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-1025.yaml | POC Details |
| CVE-2025-1026 | 8.6 HIGH | Spatie Browsershot 安全漏洞 |
| CVE-2025-1022 | 8.2 HIGH | Spatie Browsershot 安全漏洞 |
| CVE-2024-57598 | Bento4 安全漏洞 | |
| CVE-2024-54853 | Skybox Change Manager 安全漏洞 | |
| CVE-2024-57699 | Netplex Json-smart 安全漏洞 | |
| CVE-2024-57068 | form 安全漏洞 | |
| CVE-2024-57520 | Asterisk 安全漏洞 | |
| CVE-2020-36084 | SourceCodester Responsive E-Learning System 安全漏洞 | |
| CVE-2024-57067 | dot-querystring 安全漏洞 | |
| CVE-2024-57069 | expand-object 安全漏洞 | |
| CVE-2024-57064 | Syncfusion ej2-spreadsheet 安全漏洞 | |
| CVE-2024-57071 | PHP Parser 安全漏洞 | |
| CVE-2024-57063 | php-date-formatter 安全漏洞 | |
| CVE-2024-57065 | Utile 安全漏洞 | |
| CVE-2024-57078 | cli-util 安全漏洞 | |
| CVE-2024-57072 | module-from-string 安全漏洞 | |
| CVE-2024-57084 | dot-properties 安全漏洞 | |
| CVE-2024-57066 | defaults 安全漏洞 | |
| CVE-2024-57076 | ajax-request 安全漏洞 | |
| CVE-2024-57080 | vxe-table 安全漏洞 |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet