Ajenti
Security Risk Profile
64
/100
highSecurity Risk Score
Comprehensive risk assessment based on 14 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 30, 2014 to present
14
Total CVEs
8
Critical+High
0
Exploited
4
Unpatched
Threat Assessment
Avg CVSS
7.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
64/100
high
Severity Distribution
Critical
2High
6Medium
6Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
XSS
3
2
OS Command Injection
2
3
Race Condition
1
4
Infoleak
1
5
Path Traversal
1
Most Affected Products
1. Ajenti Ajenti33
2. pip/ajenti3
3. pip/ajenti.plugin.core2
4. Ajenti Ajenti Plugin Core2
5. pip/ajenti-panel1
Recent Vulnerabilities
See more →CVE-2026-40178
CVSS 6.9medium
ajenti.plugin.core has a race conditions in 2FA
4/10/2026
CVE-2026-40177
CVSS 9.3critical
Password bypass when 2FA is activated
4/10/2026
CVE-2026-35175
CVSS 7.2high
Ajenti has an authorization bypass during custom package installation
4/3/2026
CVE-2026-27975
CVSS 9.8EPSS 0%critical
Ajenti has a potential Remote Code Execution
2/26/2026
CVE-2020-37002
CVSS 8.7high
Ajenti 2.1.36 Authenticated Remote Code Execution
1/29/2026🔧 No Patch
CVE-2019-25066
CVSS 8.8high
ajenti API privileges management
6/9/2022
CVE-2018-18548
CVSS 6.1medium
10/24/2018🔧 No Patch
CVE-2018-1000126
CVSS 7.5high
3/13/2018🔧 No Patch
CVE-2018-1000083
CVSS 5.3medium
3/13/2018🔧 No Patch
CVE-2018-1000082
CVSS 8.8high
3/13/2018🔧 No Patch
Monitor Ajenti in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.