Skip to content
Noroxi

fit2cloud records

77 published records for vendor fit2cloud.

All records

77 records
  • CVE-2023-22463
    60This week

    KubePi's Hardcoded Jwtsigkeys allows malicious actor to login with a forged JWT token

    CriticalCVSS 9.8Proof of conceptEPSS 70%

    fit2cloud · kubepiJan 4, 2023

  • KubeOperator is vulnerable to unauthorized access to system API

    CriticalCVSS 9.8Proof of conceptEPSS 67%

    fit2cloud · kubeoperatorJan 13, 2023

  • a sqlinjection in 1Panel

    CriticalCVSS 9.8Proof of conceptEPSS 29%

    fit2cloud · 1panelJul 18, 2024

  • JumpServer's insecure Ansible playbook validation leads to RCE in Celery

    CriticalCVSS 9.9No exploitEPSS 6%

    fit2cloud · jumpserverMar 29, 2024

  • JumpServer vulnerable to Jinja2 template injection in Ansible leads to RCE in Celery

    CriticalCVSS 9.9No exploitEPSS 6%

    fit2cloud · jumpserverMar 29, 2024

  • 1Panel SQL injection

    CriticalCVSS 9.8No exploitEPSS 5%

    fit2cloud · 1panelJul 18, 2024

  • Command injection vulnerability in module management function in CloudExplorer Lite

    CriticalCVSS 9.8No exploitEPSS 3%

    fit2cloud · cloudexplorer liteAug 4, 2023

  • 1Panel swap baseApi.UpdateDeviceSwap command injection

    CriticalCVSS 9.8No exploitEPSS 3%

    fit2cloud · 1panelMar 9, 2024

  • Remote code execution on the host system via MongoDB shell in jumpserver

    CriticalCVSS 9.9No exploitEPSS 2%

    fit2cloud · jumpserverSep 27, 2023

  • Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command

    CriticalCVSS 9.8No exploitEPSS 2%

    fit2cloud · jumpserverNov 28, 2023

  • JumpServer session replays download without authentication

    MediumCVSS 5.3Proof of conceptEPSS 59%

    fit2cloud · jumpserverSep 15, 2023

  • Arbitrary File Write in Ansible Playbooks leads to RCE in Jumpserver

    CriticalCVSS 9.8No exploitEPSS 1%

    fit2cloud · jumpserverJul 18, 2024

  • SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService

    CriticalCVSS 9.8No exploitEPSS 1%

    fit2cloud · rackshiftSep 14, 2023

  • 1Panel Agent Bypasses Certificate Verification Leading to Arbitrary Command Execution

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    fit2cloud · 1panelAug 1, 2025

  • JumpServer Koko vulnerable to Command Injection for Kubernetes Connection

    CriticalCVSS 9.9No exploitEPSS 1%

    fit2cloud · jumpserverMar 16, 2023

  • 1Panel arbitrary file write vulnerability exists in the background

    CriticalCVSS 9.8No exploitEPSS 1%

    fit2cloud · 1panelAug 10, 2023

  • SSH public key login without private key challenge if mfa is enabled in jumpserver

    CriticalCVSS 9.8No exploitEPSS 1%

    fit2cloud · jumpserverSep 27, 2023

  • CloudExplorer Lite permission bypass vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    fit2cloud · cloudexplorer liteOct 30, 2023

  • Weak passwords allowed in cloudexplorer-lite

    CriticalCVSS 9.8No exploitEPSS 0%

    fit2cloud · cloudexplorer liteJun 27, 2023

  • CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

    CriticalCVSS 9.8No exploitEPSS 0%

    fit2cloud · cordys crmFeb 12, 2026

  • Command injection in firewall ip functionality in 1Panel

    HighCVSS 8.8No exploitEPSS 6%

    fit2cloud · 1panelJul 18, 2023

  • SQLBot prompt injection allows arbitrary SQL execution and remote code execution

    CriticalCVSS 9.4No exploitEPSS 1%

    fit2cloud · sqlbotMay 5, 2026

  • 1Panel vulnerable to ommand injection when entering the container terminal

    HighCVSS 8.8No exploitEPSS 2%

    fit2cloud · 1panelJul 5, 2023

  • 1Panel vulnerable to command injection when adding container repositories

    HighCVSS 8.8No exploitEPSS 2%

    fit2cloud · 1panelJul 5, 2023

  • Path traversal in Jumpserver

    HighCVSS 8.8Proof of conceptEPSS 2%

    fit2cloud · jumpserverSep 27, 2023