Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.50% | — | Control ID Panel Project Control ID Panel | 9/1/2023 | 17/6/2026 | A vulnerability was found in Control iD Gerencia Web 1.30. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation of the argument Nome leads to cross site scripting. The attack can be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Control-webpanel Webpanel | 5/1/2023 | 17/6/2026 | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter. | |
| Modificada | Media (6.1) | 0.57% | — | TRI Panel Builder | 27/12/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add_post_content_filtered_to_search_sql of the file ModularContent/SearchFilter.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 71% | 💥 Exploit | Control-webpanel Webpanel | 26/12/2022 | 17/6/2026 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be… | |
| Modificada | Crítica (9.8) | 55% | — | Control-webpanel Webpanel | 26/12/2022 | 17/6/2026 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder. | |
| Modificada | Alta (7.8) | 0.23% | — | Vestacp Control Panel | 13/11/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The manipulation leads to argument injection. An attack has to be approached locally. The name of the patch is… | |
| Modificada | Alta (7.2) | 5.6% | — | Vestacp Control PanelVestacp Vesta Control Panel | 24/10/2022 | 17/6/2026 | myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint. | |
| Modificada | Alta (7.5) | 0.84% | — | Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Ktp400 Basic FirmwareSiemens Simatic HMI Ktp700 Basic FirmwareSiemens Simatic HMI Ktp900 Basic Firmware+6 | 11/10/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic… | |
| Modificada | Media (6.1) | 0.57% | — | Hestiacp Control Panel | 18/8/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Alta (8.8) | 1.3% | — | Hestiacp Control Panel | 5/8/2022 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. | |
| Modificada | Alta (7.2) | 1.3% | — | Hestiacp Control Panel | 5/8/2022 | 17/6/2026 | Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. | |
| Modificada | Alta (8.8) | 48% | — | Hestiacp Control Panel | 27/7/2022 | 17/6/2026 | OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5. | |
| Modificada | Media (6.1) | 0.53% | — | Vestacp Vesta Control Panel | 19/7/2022 | 17/6/2026 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php. | |
| Modificada | Media (6.1) | 0.53% | — | Vestacp Vesta Control Panel | 19/7/2022 | 17/6/2026 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php. | |
| Modificada | Media (6.1) | 0.53% | — | Vestacp Vesta Control Panel | 19/7/2022 | 17/6/2026 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php. | |
| Modificada | Media (6.1) | 0.53% | — | Vestacp Vesta Control Panel | 19/7/2022 | 17/6/2026 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php. | |
| Modificada | Alta (7.5) | 0.89% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+15 | 11/7/2022 | 17/6/2026 | In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected. | |
| Modificada | Alta (7.5) | 0.89% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+15 | 11/7/2022 | 17/6/2026 | In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected. | |
| Modificada | Crítica (9.3) | 1.4% | — | Shackerpanel Project Shackerpanel | 11/7/2022 | 17/6/2026 | The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (8.8) | 20% | — | Control-webpanel Webpanel | 7/7/2022 | 17/6/2026 | Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user. | |
| Modificada | Media (5.9) | 2.0% | — | Control-webpanel Webpanel | 7/7/2022 | 17/6/2026 | The password reset token in CWP v0.9.8.1126 is generated using known or predictable values. | |
| Modificada | Crítica (9.8) | 57% | — | Control-webpanel Webpanel | 7/7/2022 | 17/6/2026 | A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request. | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Extreme Feedback Panel | 30/6/2022 | 17/6/2026 | Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Crítica (9.8) | 1.3% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 2/6/2022 | 17/6/2026 | EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database. | |
| Modificada | Media (5.4) | 0.49% | — | PHP Mysql Admin Panel Generator Project PHP Mysql Admin Panel Generator | 28/4/2022 | 9/7/2026 | A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php. |