cockpit-hq has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 4.2 (medium).
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.2
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-82449Medium· 5.3Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification29CVE-2026-105217Low· 3.1Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token17
cockpit-hq vulnerabilities
CVEs affecting cockpit-hq, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-105217Low· 3.1Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token
Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can p…
▾ Sunlitcockpit-hq · cockpitvia NVD
CVE-2026-82449Medium· 5.3Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification
Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response times across multiple requests to determine which acc…
▾ Sunlitcockpit-hq · cockpitEPSS 0.42%via NVD