ajenti-panel
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ajenti-panelpage 1 of 1
- CVE-2018-1000080MEDIUMCVSS 6.5EG 6.52018-03-13
vulnerable: 0.10 ... 2.2.9 (124 versions)
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is ma…
- CVE-2018-1000081HIGHCVSS 7.5EG 7.52018-03-13
vulnerable: 0.10 ... 2.2.9 (124 versions)
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant str…
- CVE-2018-1000082HIGHCVSS 8.8EG 8.82018-03-13
vulnerable: 0.10 ... 2.2.9 (124 versions)
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable…
- CVE-2018-1000083MEDIUMCVSS 5.3EG 5.32018-03-13
vulnerable: 0.10 ... 2.2.9 (124 versions)
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool r…
- CVE-2018-1000126HIGHCVSS 7.5EG 7.52018-03-13
vulnerable: 0.10 ... 2.2.9 (124 versions)
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via…
- CVE-2026-35175MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.2.152026-04-06
vulnerable: 0.10 ... 2.2.9 (126 versions)
Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser. This vulnerability is fixed…
Check whether ajenti-panel is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ajenti-panel CVEs against the assets you own.
Start Free Scan →