It Novum maintains a focused vulnerability footprint around openitcockpit, a monitoring and IT operations platform that occupies a specialized niche in the infrastructure-management landscape. The vendor's disclosures span parser and input-handling patterns characteristic of web-based administrative tools. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by It Novum over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10789CRITICAL openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app | Mar 25, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-10227MEDIUM openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. | Dec 31, 2019 | 6.1 | 30 | NO | YES |
CVE-2026-24893HIGH openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerab | Apr 14, 2026 | 8.8 | 29 | NO | NO |
CVE-2019-15494CRITICAL openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. | Aug 23, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-15490CRITICAL openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21. | Aug 23, 2019 | 9.8 | 29 | NO | NO |
CVE-2026-24892HIGH openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contain | Feb 20, 2026 | 8.8 | 27 | NO | NO |
CVE-2019-15491HIGH openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. | Aug 23, 2019 | 8.8 | 26 | NO | NO |
CVE-2023-36663HIGH it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface. | Jun 25, 2023 | 8.8 | 25 | NO | NO |
CVE-2026-24891HIGH openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserializatio | Feb 20, 2026 | 7.5 | 24 | NO | NO |
CVE-2020-10792HIGH openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host | Mar 20, 2020 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by It Novum.
Media articles that mention a CVE ID that affects a product developed by It Novum — matched by CVE ID, not by vendor name.