ajenti-panel
Ajenti core based panel
Activity
- Latest release
- 3d ago
- Total releases
- 129
- Cadence
- ~43 days
- Last 12 months
- 5
Details
- First release
- Feb 08, 2015
| Version | Released | |
|---|---|---|
2.2.17
patch
5 CVEs
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.17
patch
Dependencies (3)
|
|
2.2.16
patch
5 CVEs
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.16
patch
Dependencies (3)
|
|
2.2.15
patch
5 CVEs
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.15
patch
Dependencies (3)
|
|
2.2.13
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.13
patch
Dependencies (3)
|
|
2.2.12
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.12
patch
Dependencies (3)
|
|
2.2.11
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.11
patch
Dependencies (3)
|
|
2.2.10
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.10
patch
|
|
2.2.9
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.9
patch
|
|
2.2.8
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.8
patch
|
|
2.2.7
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.7
patch
|
|
2.2.6
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.6
patch
|
|
2.2.5
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.5
patch
|
|
2.2.4
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.4
patch
|
|
2.2.3
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.3
patch
|
|
2.2.1
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.1
patch
|
|
2.2.0
minor
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.2.0
minor
|
|
2.1.44
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.44
patch
|
|
2.1.43
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.43
patch
|
|
2.1.42
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.42
patch
|
|
2.1.40
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.40
patch
|
|
2.1.39
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.39
patch
|
|
2.1.38
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.38
patch
|
|
2.1.37
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.37
patch
|
|
2.1.36
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.36
patch
|
|
2.1.35
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.35
patch
|
|
2.1.34
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.34
patch
|
|
2.1.33
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.33
patch
|
|
2.1.32
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.32
patch
|
|
2.1.31
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.31
patch
|
|
2.1.30
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.30
patch
|
|
2.1.29
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.29
patch
|
|
2.1.28
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.28
patch
|
|
2.1.27
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.27
patch
|
|
2.1.26
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.26
patch
|
|
2.1.25
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.25
patch
|
|
2.1.24
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.24
patch
|
|
2.1.23
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.23
patch
|
|
2.1.22
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.22
patch
|
|
2.1.21
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.21
patch
|
|
2.1.20
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.20
patch
|
|
2.1.19
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.19
patch
|
|
2.1.18
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.18
patch
|
|
2.1.17
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.17
patch
|
|
2.1.16
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.16
patch
|
|
2.1.15
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.15
patch
|
|
2.1.14
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.14
patch
|
|
2.1.13
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.13
patch
|
|
2.1.12
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.12
patch
|
|
2.1.11
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.11
patch
|
|
2.1.10
patch
6 CVEs
CVE-2026-35175
PYSEC-2026-2339
GHSA-73jv-44c3-j5p2
Jul 13, 2026
Ajenti has an authorization bypass during custom package installation
High
Network
Low
Low
None
ImpactAn authenticated user (using the PatchesThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 114 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.44
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2018-1000126
PYSEC-2018-113
Mar 13, 2018
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000082
PYSEC-2018-111
Mar 13, 2018
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000083
PYSEC-2018-112
Mar 13, 2018
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000080
PYSEC-2018-109
Mar 13, 2018
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev
CVE-2018-1000081
PYSEC-2018-110
Mar 13, 2018
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. Affected versions
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
+ 112 more Show less
0.21
0.22
0.23
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.4
0.5
0.6
0.7
0.8
0.9
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.70
2.0.71
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.4
2.1.40
2.1.42
2.1.43
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.44
2.2.0
2.2.1
2.2.10
2.2.11
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
References Updated Oct 09, 2025 · Source: OSV.dev |
2.1.10
patch
|