fit2cloud records
77 published records for vendor fit2cloud.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 45.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')6
- CWE-862 Missing Authorization6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
The weakness classes this vendor ships most often: where to look.
CWEAll records
77 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2023-22463Proof of concept | KubePi's Hardcoded Jwtsigkeys allows malicious actor to login with a forged JWT tokenfit2cloud · kubepi · CWE-798 | Critical9.8 | — | 69.7% | Jan 4, 2023 |
59Plan | CVE-2023-22480Proof of concept | KubeOperator is vulnerable to unauthorized access to system APIfit2cloud · kubeoperator · CWE-285 | Critical9.8 | — | 66.8% | Jan 13, 2023 |
48Plan | CVE-2024-39907Proof of concept | a sqlinjection in 1Panelfit2cloud · 1panel · CWE-89 | Critical9.8 | — | 29.2% | Jul 18, 2024 |
41Plan | CVE-2024-29201No exploit | JumpServer's insecure Ansible playbook validation leads to RCE in Celeryfit2cloud · jumpserver · CWE-94 | Critical9.9 | — | 5.9% | Mar 29, 2024 |
41Plan | CVE-2024-29202No exploit | JumpServer vulnerable to Jinja2 template injection in Ansible leads to RCE in Celeryfit2cloud · jumpserver · CWE-94 | Critical9.9 | — | 5.9% | Mar 29, 2024 |
40Plan | CVE-2024-39911No exploit | 1Panel SQL injectionfit2cloud · 1panel · CWE-89 | Critical9.8 | — | 4.5% | Jul 18, 2024 |
40Plan | CVE-2023-38692No exploit | Command injection vulnerability in module management function in CloudExplorer Litefit2cloud · cloudexplorer lite · CWE-78 | Critical9.8 | — | 3.4% | Aug 4, 2023 |
40Plan | CVE-2024-2352No exploit | 1Panel swap baseApi.UpdateDeviceSwap command injectionfit2cloud · 1panel · CWE-77 | Critical9.8 | — | 3.0% | Mar 9, 2024 |
40Plan | CVE-2023-43651No exploit | Remote code execution on the host system via MongoDB shell in jumpserverfit2cloud · jumpserver · CWE-94 | Critical9.9 | — | 2.1% | Sep 27, 2023 |
40Plan | CVE-2023-48193No exploit | Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command fit2cloud · jumpserver | Critical9.8 | — | 2.0% | Nov 28, 2023 |
39Monitor | CVE-2023-42442Proof of concept | JumpServer session replays download without authenticationfit2cloud · jumpserver · CWE-287 | Medium5.3 | — | 58.5% | Sep 15, 2023 |
39Monitor | CVE-2024-40629No exploit | Arbitrary File Write in Ansible Playbooks leads to RCE in Jumpserverfit2cloud · jumpserver · CWE-22 | Critical9.8 | — | 1.3% | Jul 18, 2024 |
39Monitor | CVE-2023-42405No exploit | SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskServicefit2cloud · rackshift · CWE-89 | Critical9.8 | — | 1.1% | Sep 14, 2023 |
39Monitor | CVE-2025-54424Proof of concept | 1Panel Agent Bypasses Certificate Verification Leading to Arbitrary Command Executionfit2cloud · 1panel · CWE-77 | Critical9.8 | — | 0.9% | Aug 1, 2025 |
39Monitor | CVE-2023-28110No exploit | JumpServer Koko vulnerable to Command Injection for Kubernetes Connectionfit2cloud · jumpserver · CWE-77 | Critical9.9 | — | 0.8% | Mar 16, 2023 |
39Monitor | CVE-2023-39966No exploit | 1Panel arbitrary file write vulnerability exists in the backgroundfit2cloud · 1panel · CWE-862 | Critical9.8 | — | 0.8% | Aug 10, 2023 |
39Monitor | CVE-2023-42818No exploit | SSH public key login without private key challenge if mfa is enabled in jumpserverfit2cloud · jumpserver · CWE-287 | Critical9.8 | — | 0.7% | Sep 27, 2023 |
39Monitor | CVE-2023-44397No exploit | CloudExplorer Lite permission bypass vulnerabilityfit2cloud · cloudexplorer lite · CWE-287 | Critical9.8 | — | 0.6% | Oct 30, 2023 |
39Monitor | CVE-2023-34240No exploit | Weak passwords allowed in cloudexplorer-litefit2cloud · cloudexplorer lite · CWE-521 | Critical9.8 | — | 0.5% | Jun 27, 2023 |
39Monitor | CVE-2025-70981No exploit | CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.fit2cloud · cordys crm · CWE-89 | Critical9.8 | — | 0.3% | Feb 12, 2026 |
37Monitor | CVE-2023-37477No exploit | Command injection in firewall ip functionality in 1Panelfit2cloud · 1panel · CWE-78 | High8.8 | — | 5.8% | Jul 18, 2023 |
37Monitor | CVE-2026-33324No exploit | SQLBot prompt injection allows arbitrary SQL execution and remote code executionfit2cloud · sqlbot · CWE-89 | Critical9.4 | — | 0.8% | May 5, 2026 |
36Monitor | CVE-2023-36458No exploit | 1Panel vulnerable to ommand injection when entering the container terminalfit2cloud · 1panel · CWE-77 | High8.8 | — | 2.3% | Jul 5, 2023 |
36Monitor | CVE-2023-36457No exploit | 1Panel vulnerable to command injection when adding container repositoriesfit2cloud · 1panel · CWE-77 | High8.8 | — | 2.3% | Jul 5, 2023 |
36Monitor | CVE-2023-42819Proof of concept | Path traversal in Jumpserverfit2cloud · jumpserver · CWE-22 | High8.8 | — | 2.2% | Sep 27, 2023 |
- CVE-2023-2246360This week
KubePi's Hardcoded Jwtsigkeys allows malicious actor to login with a forged JWT token
CriticalCVSS 9.8Proof of conceptEPSS 70%fit2cloud · kubepiJan 4, 2023
- CVE-2023-2248059Plan
KubeOperator is vulnerable to unauthorized access to system API
CriticalCVSS 9.8Proof of conceptEPSS 67%fit2cloud · kubeoperatorJan 13, 2023
- CVE-2024-3990748Plan
a sqlinjection in 1Panel
CriticalCVSS 9.8Proof of conceptEPSS 29%fit2cloud · 1panelJul 18, 2024
- CVE-2024-2920141Plan
JumpServer's insecure Ansible playbook validation leads to RCE in Celery
CriticalCVSS 9.9No exploitEPSS 6%fit2cloud · jumpserverMar 29, 2024
- CVE-2024-2920241Plan
JumpServer vulnerable to Jinja2 template injection in Ansible leads to RCE in Celery
CriticalCVSS 9.9No exploitEPSS 6%fit2cloud · jumpserverMar 29, 2024
- CVE-2024-3991140Plan
1Panel SQL injection
CriticalCVSS 9.8No exploitEPSS 5%fit2cloud · 1panelJul 18, 2024
- CVE-2023-3869240Plan
Command injection vulnerability in module management function in CloudExplorer Lite
CriticalCVSS 9.8No exploitEPSS 3%fit2cloud · cloudexplorer liteAug 4, 2023
- CVE-2024-235240Plan
1Panel swap baseApi.UpdateDeviceSwap command injection
CriticalCVSS 9.8No exploitEPSS 3%fit2cloud · 1panelMar 9, 2024
- CVE-2023-4365140Plan
Remote code execution on the host system via MongoDB shell in jumpserver
CriticalCVSS 9.9No exploitEPSS 2%fit2cloud · jumpserverSep 27, 2023
- CVE-2023-4819340Plan
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command
CriticalCVSS 9.8No exploitEPSS 2%fit2cloud · jumpserverNov 28, 2023
- CVE-2023-4244239Monitor
JumpServer session replays download without authentication
MediumCVSS 5.3Proof of conceptEPSS 59%fit2cloud · jumpserverSep 15, 2023
- CVE-2024-4062939Monitor
Arbitrary File Write in Ansible Playbooks leads to RCE in Jumpserver
CriticalCVSS 9.8No exploitEPSS 1%fit2cloud · jumpserverJul 18, 2024
- CVE-2023-4240539Monitor
SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService
CriticalCVSS 9.8No exploitEPSS 1%fit2cloud · rackshiftSep 14, 2023
- CVE-2025-5442439Monitor
1Panel Agent Bypasses Certificate Verification Leading to Arbitrary Command Execution
CriticalCVSS 9.8Proof of conceptEPSS 1%fit2cloud · 1panelAug 1, 2025
- CVE-2023-2811039Monitor
JumpServer Koko vulnerable to Command Injection for Kubernetes Connection
CriticalCVSS 9.9No exploitEPSS 1%fit2cloud · jumpserverMar 16, 2023
- CVE-2023-3996639Monitor
1Panel arbitrary file write vulnerability exists in the background
CriticalCVSS 9.8No exploitEPSS 1%fit2cloud · 1panelAug 10, 2023
- CVE-2023-4281839Monitor
SSH public key login without private key challenge if mfa is enabled in jumpserver
CriticalCVSS 9.8No exploitEPSS 1%fit2cloud · jumpserverSep 27, 2023
- CVE-2023-4439739Monitor
CloudExplorer Lite permission bypass vulnerability
CriticalCVSS 9.8No exploitEPSS 1%fit2cloud · cloudexplorer liteOct 30, 2023
- CVE-2023-3424039Monitor
Weak passwords allowed in cloudexplorer-lite
CriticalCVSS 9.8No exploitEPSS 0%fit2cloud · cloudexplorer liteJun 27, 2023
- CVE-2025-7098139Monitor
CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.
CriticalCVSS 9.8No exploitEPSS 0%fit2cloud · cordys crmFeb 12, 2026
- CVE-2023-3747737Monitor
Command injection in firewall ip functionality in 1Panel
HighCVSS 8.8No exploitEPSS 6%fit2cloud · 1panelJul 18, 2023
- CVE-2026-3332437Monitor
SQLBot prompt injection allows arbitrary SQL execution and remote code execution
CriticalCVSS 9.4No exploitEPSS 1%fit2cloud · sqlbotMay 5, 2026
- CVE-2023-3645836Monitor
1Panel vulnerable to ommand injection when entering the container terminal
HighCVSS 8.8No exploitEPSS 2%fit2cloud · 1panelJul 5, 2023
- CVE-2023-3645736Monitor
1Panel vulnerable to command injection when adding container repositories
HighCVSS 8.8No exploitEPSS 2%fit2cloud · 1panelJul 5, 2023
- CVE-2023-4281936Monitor
Path traversal in Jumpserver
HighCVSS 8.8Proof of conceptEPSS 2%fit2cloud · jumpserverSep 27, 2023