Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

cockpit-hq/cockpit — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in cockpit-hq/cockpit, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations affecting the cockpit-hq/cockpit project, specifically targeting its integration with web console interfaces. It aggregates security vulnerabilities identified in the cockpit-hq/cockpit software, covering releases and patches from 2019 through 2024. The collected data reflects the evolving threat landscape as the platform expanded its support for containerized workloads and remote management capabilities. Visitors to this resource can track vendor advisories related to cockpit-hq/cockpit to stay informed about newly discovered security flaws. Users may also deepen their understanding of specific weakness classes, such as improper input validation or authorization bypasses, by examining how they manifest within this particular application context. Additionally, the page serves as a historical record, allowing administrators and security researchers to look up the vulnerability history of cockpit-hq/cockpit to assess past risks and evaluate the effectiveness of subsequent remediation efforts. This centralized view aids in prioritizing patching strategies and understanding the systemic impact of reported issues on enterprise infrastructure. The information provided is intended to support informed decision-making regarding system hardening and compliance requirements without promoting any specific vendor or product endorsement. All entries are sourced from official disclosures and recognized security databases to ensure accuracy and reliability for technical audiences.

Vendor: cockpit-hq

CVE ID Title CVSS Severity Published
CVE-2025-1025 Cockpit 安全漏洞 CWE-434 7.5 High 2025-02-05
CVE-2023-4451 Cross-site Scripting (XSS) - Reflected in cockpit-hq/cockpit CWE-79 5.4 - 2023-08-20
CVE-2023-4433 Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit CWE-79 5.4 - 2023-08-19
CVE-2023-4432 Cross-site Scripting (XSS) - Reflected in cockpit-hq/cockpit CWE-79 5.4 - 2023-08-19
CVE-2023-4422 Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit CWE-79 5.4 - 2023-08-18
CVE-2023-4395 Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit CWE-79 5.4 - 2023-08-17
CVE-2023-4321 Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit CWE-79 5.4 - 2023-08-14
CVE-2023-4196 Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit CWE-79 5.4 - 2023-08-06
CVE-2023-4195 PHP Remote File Inclusion in cockpit-hq/cockpit CWE-98 8.8 - 2023-08-06
CVE-2023-1313 Unrestricted Upload of File with Dangerous Type in cockpit-hq/cockpit CWE-434 8.8 - 2023-03-10
CVE-2023-1160 Use of Platform-Dependent Third Party Components in cockpit-hq/cockpit CWE-1103 7.5 - 2023-03-03
CVE-2023-0780 Improper Restriction of Rendered UI Layers or Frames in cockpit-hq/cockpit CWE-1021 5.4 - 2023-02-11
CVE-2023-0759 Privilege Chaining in cockpit-hq/cockpit CWE-268 8.8 - 2023-02-09
CVE-2022-2818 Improper Removal of Sensitive Information Before Storage or Transfer in cockpit-hq/cockpit CWE-212 9.8 Critical 2022-08-15
CVE-2022-2713 Insufficient Session Expiration in cockpit-hq/cockpit CWE-613 9.8 - 2022-08-08

All 15 known CVE vulnerabilities affecting cockpit-hq/cockpit with full Chinese analysis, references, and POCs where available.