Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.46% | — | Pterodactyl Panel | 3/5/2024 | 17/6/2026 | Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrator account on the panel. Specifically, the following things are… | |
| Analizada | Alta (8.8) | 2.3% | — | Control-webpanel Webpanel | 3/5/2024 | 17/6/2026 | Control Web Panel mysql_manager Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is required to exploit this vulnerability. The specific flaw exists within the mysql_manager module.… | |
| Analizada | Alta (7.8) | 0.77% | — | Control-webpanel Webpanel | 3/5/2024 | 17/6/2026 | Control Web Panel wloggui Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Control Web Panel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Crítica (9.8) | 1.8% | — | Control-webpanel Webpanel | 3/5/2024 | 17/6/2026 | Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of… | |
| Analizada | Alta (8.8) | 2.6% | — | Control-webpanel Webpanel | 3/5/2024 | 17/6/2026 | Control Web Panel dns_zone_editor Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is required to exploit this vulnerability. The specific flaw exists within the dns_zone_editor… | |
| Analizada | Media (5.9) | 0.38% | — | Fit2cloud 1panel | 18/4/2024 | 17/6/2026 | 1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol instead hmac.Equal. This may lead to a timing attack vulnerability. This vulnerability is fixed in 1.10.3-lts. | |
| Aplazada | Media (5.4) | 0.20% | — | Ertano MihanpanelAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ertano MihanPanel.This issue affects MihanPanel: from n/a before 12.7. | |
| Aplazada | Alta (7.5) | 0.51% | — | Cerberus PRO EN Engineering ToolAICerberus PRO EN Fire Panel Fc72xAICerberus PRO EN X200 Cloud DistributionAICerberus PRO EN X300 Cloud DistributionAI+11 | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions),… | |
| Aplazada | Alta (7.5) | 0.83% | — | Cerberus PRO EN Engineering ToolAICerberus PRO EN Fire Panel Fc72xAICerberus PRO EN X200 Cloud DistributionAICerberus PRO EN X300 Cloud DistributionAI+11 | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions),… | |
| Modificada | Crítica (9.8) | 0.81% | — | Siemens Cerberus PRO EN Engineering ToolSiemens Cerberus PRO EN Fire Panel Fc72xSiemens Cerberus PRO EN X200 Cloud DistributionSiemens Cerberus PRO EN X300 Cloud Distribution+5 | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < IP6 SR3), Cerberus PRO EN Fire Panel FC72x IP7 (All versions < IP7 SR5), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions < V3.0.6602), Cerberus PRO EN X200 Cloud… | |
| Analizada | Crítica (9.8) | 3.0% | — | Fit2cloud 1panel | 10/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDeviceSwap of the file /api/v1/toolbox/device/update/swap. The manipulation of the argument Path with the input 123123123\nopen -a Calculator leads to command injection.… | |
| Analizada | Baja (3.1) | 0.47% | — | Fit2cloud 1panel | 6/3/2024 | 17/6/2026 | 1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to the console page. The vulnerability has been fixed in v1.10.1-lts. There are no known workarounds. | |
| Modificada | Media (6.1) | 0.38% | — | Code-projects Simple Admin Panel | 14/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function. | |
| Modificada | Media (5.4) | 0.41% | — | Code-projects Simple Admin Panel | 14/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function. | |
| Modificada | Media (5.4) | 0.38% | — | Code-projects Simple Admin Panel | 14/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Size Number parameter under the Add Size function. | |
| Modificada | Crítica (9.8) | 0.63% | — | Code-projects Simple Admin Panel | 14/2/2024 | 17/6/2026 | Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php. | |
| Modificada | Crítica (9.1) | 0.79% | — | Rurban Cpanel\ | 13/2/2024 | 17/6/2026 | The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service. | |
| Modificada | Crítica (9.8) | 0.58% | — | Johnsoncontrols Qolsys IQ Panel 4 FirmwareJohnsoncontrols Qolsys IQ4 HUB Firmware | 8/2/2024 | 17/6/2026 | Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings. | |
| Modificada | Alta (7.5) | 0.30% | — | Fit2cloud 1panel | 5/2/2024 | 17/6/2026 | 1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure keyword, which may cause the cookie to be sent in plain text if accessed using HTTP. This issue has been patched in version 1.9.6. | |
| Modificada | Media (5.3) | 0.61% | — | Seopanel SEO Panel | 30/1/2024 | 17/6/2026 | A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment. | |
| Modificada | Media (5.3) | 0.56% | — | Seopanel SEO Panel | 30/1/2024 | 17/6/2026 | An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames. | |
| Modificada | Media (5.3) | 0.58% | — | Seopanel SEO Panel | 30/1/2024 | 17/6/2026 | An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system. | |
| Modificada | Media (6.5) | 0.33% | — | Seopanel SEO Panel | 30/1/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets. | |
| Modificada | Crítica (9.8) | 0.53% | — | Ween Management Panel | 29/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ween Software Admin Panel allows SQL Injection. This issue affects Admin Panel: through 20231229. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Modificada | Alta (8.8) | 2.3% | — | Mgt-commerce Cloudpanel | 8/12/2023 | 17/6/2026 | File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755. |