CVE Tools

FIT2CLOUD

52 CVEs tracked since 2023. Since Jan 2023, none of them reached CISA KEV.

FIT2CLOUD CVEs per month

Jan 2023 to Mar 2026. Point at a month, or focus the strip and use the arrow keys.
FIT2CLOUD CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0140
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-0550
2023-06null or fewer
2023-0750
2023-0850
2023-0990
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-0360
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-0740
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-1270
2026-01null or fewer
2026-02null or fewer
2026-0370

Products

The products that kept showing up in FIT2CLOUD's monthly top three, with their CVEs summed over those months.

  1. Jumpserver165 months
  2. 1panel155 months
  3. Cloudexplorer Lite53 months
  4. Kubepi52 months
  5. Sqlbot51 month
  6. Cloudexplorer21 month
  7. Halo11 month
  8. Kubeoperator11 month
  9. Lina11 month
  10. Rackshift11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting FIT2CLOUD.

  1. CVE-2026-42463SQLBot: Unauthorized Access Vulnerability8.1
  2. CVE-2026-33324SQLBot prompt injection allows arbitrary SQL execution and remote code execution8.8
  3. CVE-2026-32950SQLBot: RCE via SQL Injection in Excel Upload Endpoint8.8
  4. CVE-2026-32949SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL7.5
  5. CVE-2026-32622SQLBot: Remote Code Execution via Terminology Poisoning8.8
  6. CVE-2026-31864JumpServer has a Server-Side Template Injection Leading to RCE via YAML Rendering6.8
  7. CVE-2026-31798JumpServer Improper Certificate Validation in Custom SMS API Client5.0
  8. CVE-2025-15598Dataease SQLBot JWT Token auth.py validateEmbedded signature verification3.7
  9. CVE-2025-15597Dataease SQLBot API Endpoint assistant.py access control6.3
  10. CVE-2025-70981CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.9.8
  11. CVE-2025-69285SQLBot uploadExcel Endpoint has Unauthenticated Arbitrary File Upload vulnerability6.1
  12. CVE-2025-344291Panel CSRF Web Port Configuration Change7.1
  13. CVE-2025-344301Panel CSRF Panel Name Modification4.3
  14. CVE-2025-344101Panel CSRF in Change Username Functionality Allows Account Lockout7.1
  15. CVE-2025-665081Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers6.5

The record

Peak rank
#72 in Sep 2023
Busiest month shown
Sep 2023, 9 CVEs
Months with a KEV entry
0 since Jan 2023
Monthly snapshots
9 since 2023
FIT2CLOUD's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store