agentejo CVE Vulnerabilities & Metrics

Focus on agentejo vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About agentejo Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with agentejo. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total agentejo CVEs: 28
Earliest CVE date: 10 Apr 2018, 15:29 UTC
Latest CVE date: 29 Feb 2024, 14:15 UTC

Latest CVE reference: CVE-2024-2001

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical agentejo CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.12

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 19
4.0-6.9 4
7.0-8.9 5
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS agentejo CVEs

These are the five CVEs with the highest CVSS scores for agentejo, sorted by severity first and recency.

All CVEs for agentejo

CVE-2024-2001 agentejo vulnerability CVSS: 0 29 Feb 2024, 14:15 UTC

A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.

CVE-2023-41564 agentejo vulnerability CVSS: 0 08 Sep 2023, 23:15 UTC

An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.

CVE-2023-4451 agentejo vulnerability CVSS: 0 20 Aug 2023, 15:15 UTC

Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

CVE-2023-4433 agentejo vulnerability CVSS: 0 19 Aug 2023, 01:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

CVE-2023-4432 agentejo vulnerability CVSS: 0 19 Aug 2023, 01:15 UTC

Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

CVE-2023-4422 agentejo vulnerability CVSS: 0 18 Aug 2023, 19:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CVE-2023-4395 agentejo vulnerability CVSS: 0 17 Aug 2023, 04:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

CVE-2023-4321 agentejo vulnerability CVSS: 0 14 Aug 2023, 11:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.

CVE-2023-4196 agentejo vulnerability CVSS: 0 06 Aug 2023, 18:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CVE-2023-4195 agentejo vulnerability CVSS: 0 06 Aug 2023, 18:15 UTC

PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CVE-2023-37650 agentejo vulnerability CVSS: 0 20 Jul 2023, 20:15 UTC

A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.

CVE-2023-37649 agentejo vulnerability CVSS: 0 20 Jul 2023, 20:15 UTC

Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.

CVE-2023-1313 agentejo vulnerability CVSS: 0 10 Mar 2023, 12:15 UTC

Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.

CVE-2023-1160 agentejo vulnerability CVSS: 0 03 Mar 2023, 02:15 UTC

Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.

CVE-2021-32857 agentejo vulnerability CVSS: 0 21 Feb 2023, 15:15 UTC

Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.

CVE-2023-0780 agentejo vulnerability CVSS: 0 11 Feb 2023, 02:20 UTC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.

CVE-2023-0759 agentejo vulnerability CVSS: 0 09 Feb 2023, 14:15 UTC

Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.

CVE-2022-2818 agentejo vulnerability CVSS: 0 15 Aug 2022, 11:21 UTC

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

CVE-2022-2713 agentejo vulnerability CVSS: 0 08 Aug 2022, 15:15 UTC

Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.

CVE-2020-35131 agentejo vulnerability CVSS: 7.5 08 Jan 2021, 17:15 UTC

Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.

CVE-2020-35848 agentejo vulnerability CVSS: 7.5 30 Dec 2020, 01:15 UTC

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.

CVE-2020-35847 agentejo vulnerability CVSS: 7.5 30 Dec 2020, 01:15 UTC

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

CVE-2020-35846 agentejo vulnerability CVSS: 7.5 30 Dec 2020, 01:15 UTC

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.

CVE-2020-14408 agentejo vulnerability CVSS: 4.3 17 Jun 2020, 20:15 UTC

An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.

CVE-2018-15540 agentejo vulnerability CVSS: 7.5 15 Oct 2018, 19:29 UTC

Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.

CVE-2018-15539 agentejo vulnerability CVSS: 6.8 15 Oct 2018, 19:29 UTC

Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.

CVE-2018-15538 agentejo vulnerability CVSS: 4.3 15 Oct 2018, 19:29 UTC

Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.

CVE-2017-14611 agentejo vulnerability CVSS: 6.4 10 Apr 2018, 15:29 UTC

SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.