Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Cockpit Number Of NVD 4 CRITICAL 0 HIGH 2 MEDIUM 2 LOW 0
URL https://cockpit-project.org/
Explanation It is a tool to manage Linux with a web interface like Webmin.
Cockpit aims to be intuitive and easy to use without having to read help files. The goal seems to be to have a default installation with no more than minimal installation.
Tag
  • LGPL 2.1+

Add Information URL
No Type Name URL

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
1 Cockpit 360 April 18, 2026 0 0 0 0
2 0.63 0 0 0 0
3 0.62 0 0 0 0
4 0.61 0 0 0 0
5 0.60 0 0 0 0
6 0.6 0 0 0 0
7 0.59 0 0 0 0
8 0.58 0 0 0 0
9 0.57 0 0 0 0
10 0.56 0 0 0 0
11 0.55 0 0 0 0
12 0.54 0 0 0 0
13 0.53 0 0 0 0
14 0.52 0 0 0 0
15 0.51 0 0 0 0
16 0.50 0 0 0 0
17 0.5 0 0 0 0
18 0.49 0 0 0 0
19 0.48 0 0 0 0
20 0.47 0 0 0 0
21 0.46 0 0 0 0
22 0.45 0 0 0 0
23 0.44 0 0 0 0
24 0.43 0 0 0 0
25 0.42 0 0 0 0
26 0.41 0 0 0 0
27 0.40 0 0 0 0
28 0.4 0 0 0 0
29 0.39 0 0 0 0
30 0.38 0 0 0 0
31 0.37 0 0 0 0
32 0.36 0 0 0 0
33 0.35 0 0 0 0
34 0.34 0 0 0 0
35 0.33 0 0 0 0
36 0.32 0 0 0 0
37 0.31 0 0 0 0
38 0.30 0 0 0 0
39 0.3 0 0 0 0
40 0.29 0 0 0 0
41 0.28 0 0 0 0
42 0.27 0 0 0 0
43 0.26 0 0 0 0
44 0.25 0 0 0 0
45 0.24 0 0 0 0
46 0.23 0 0 0 0
47 0.22 0 0 0 0
48 0.21 0 0 0 0
49 0.20 0 0 0 0
50 0.2 0 0 0 0
51 0.19 0 0 0 0
52 0.18 0 0 0 0
53 0.17 0 0 0 0
54 0.16 0 0 0 0
55 0.15 0 0 0 0
56 0.14 0 0 0 0
57 0.13 0 0 0 0
58 0.12 0 0 0 0
59 0.117 0 0 0 0
60 0.116 0 0 0 0
61 0.115 0 0 0 0
62 0.114 0 0 0 0
63 0.113 0 0 0 0
64 0.112 0 0 0 0
65 0.111 0 0 0 0
66 0.110 0 0 0 0
67 0.11 0 0 0 0
68 0.109 0 0 0 0
69 0.108 0 0 0 0
70 0.107 0 0 0 0
71 0.106 0 0 0 0
72 0.105 0 0 0 0
73 0.104 0 0 0 0
74 0.103 0 0 0 0
75 0.102 0 0 0 0
76 0.101 0 0 0 0
77 0.100 0 0 0 0
78 0.10 0 0 0 0
79 0.0.1 0 0 0 0
80 255.1 0 0 0 0
81 251.3 0 0 0 0
82 251.2 0 0 0 0
83 251.1 0 0 0 0
84 244.1 0 0 0 0
85 238.2 0 0 0 0
86 238.1 0 0 0 0
87 184.1 0 0 0 0
88 173.2 0 0 0 0
89 173.1 0 0 0 0
90 1.2.0 0 0 0 0
91 1.1.0 0 0 0 0
92 1.0.0 0 0 0 0
93 0.99 0 0 0 0
94 0.98 0 0 0 0
95 0.97 0 0 0 0
96 0.96 0 0 0 0
97 0.95 0 0 0 0
98 0.94 0 0 0 0
99 0.93 0 0 0 0
100 0.92 0 0 0 0
101 0.91 0 0 0 0
102 0.90 0 0 0 0
103 0.9 0 0 0 0
104 0.89 0 0 0 0
105 0.88 0 0 0 0
106 0.87 0 0 0 0
107 0.86 0 0 0 0
108 0.85 0 0 0 0
109 0.84 0 0 0 0
110 0.83 0 0 0 0
111 0.82 0 0 0 0
112 0.81 0 0 0 0
113 0.80 0 0 0 0
114 0.8 0 0 0 0
115 0.79 0 0 0 0
116 0.78 0 0 0 0
117 0.77 0 0 0 0
118 0.76 0 0 0 0
119 0.75 0 0 0 0
120 0.74 0 0 0 0
121 0.73 0 0 0 0
122 0.72 0 0 0 0
123 0.71 0 0 0 0
124 0.70 0 0 0 0
125 0.7 0 0 0 0
126 0.69 0 0 0 0
127 0.68 0 0 0 0
128 0.67 0 0 0 0
129 0.66 0 0 0 0
130 0.65 0 0 0 0
131 0.64 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
1 7.5
5.0
HIGH
Network
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates t… CWE-295
Improper Certificate Validation 
CVE-2021-3698 cpe:2.3:a:cockpit-project:cockpit:*:* 260 2024-11-21 15:22
2022-03-11
Show GitHub Exploit DB Packet Storm
2 4.3
4.3
MEDIUM
Network
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be use… - CVE-2021-3660 cpe:2.3:a:cockpit-project:cockpit:*:* 254 2024-11-21 15:22
2022-03-11
Show GitHub Exploit DB Packet Storm
3 6.5
4.0
MEDIUM
Network
An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-35850 cpe:2.3:a:cockpit-project:cockpit:234:* 2024-11-21 14:28
2020-12-30
Show GitHub Exploit DB Packet Storm
4 7.5
5.0
HIGH
Network
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted re… CWE-909
 Missing Initialization of Resource
CVE-2019-3804 cpe:2.3:a:cockpit-project:cockpit:*:* 184 2024-11-21 13:42
2019-03-27
Show GitHub Exploit DB Packet Storm