Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.50%—Control ID Panel Project Control ID Panel9/1/202317/6/2026
A vulnerability was found in Control iD Gerencia Web 1.30. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation of the argument Nome leads to cross site scripting. The attack can be launched remotely. The exploit has been…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitControl-webpanel Webpanel5/1/202317/6/2026
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
ModificadaMedia (6.1)0.57%—TRI Panel Builder27/12/202217/6/2026
A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add_post_content_filtered_to_search_sql of the file ModularContent/SearchFilter.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed…
ModificadaCrítica (9.8)71%💥 ExploitControl-webpanel Webpanel26/12/202217/6/2026
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be…
ModificadaCrítica (9.8)55%—Control-webpanel Webpanel26/12/202217/6/2026
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.
ModificadaAlta (7.8)0.23%—Vestacp Control Panel13/11/202217/6/2026
A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The manipulation leads to argument injection. An attack has to be approached locally. The name of the patch is…
ModificadaAlta (7.2)5.6%—Vestacp Control PanelVestacp Vesta Control Panel24/10/202217/6/2026
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.
ModificadaAlta (7.5)0.84%—Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Ktp400 Basic FirmwareSiemens Simatic HMI Ktp700 Basic FirmwareSiemens Simatic HMI Ktp900 Basic Firmware+611/10/202217/6/2026
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic…
ModificadaMedia (6.1)0.57%—Hestiacp Control Panel18/8/202217/6/2026
A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
ModificadaAlta (8.8)1.3%—Hestiacp Control Panel5/8/202217/6/2026
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
ModificadaAlta (7.2)1.3%—Hestiacp Control Panel5/8/202217/6/2026
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
ModificadaAlta (8.8)48%—Hestiacp Control Panel27/7/202217/6/2026
OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.
ModificadaMedia (6.1)0.53%—Vestacp Vesta Control Panel19/7/202217/6/2026
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.
ModificadaMedia (6.1)0.53%—Vestacp Vesta Control Panel19/7/202217/6/2026
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.
ModificadaMedia (6.1)0.53%—Vestacp Vesta Control Panel19/7/202217/6/2026
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.
ModificadaMedia (6.1)0.53%—Vestacp Vesta Control Panel19/7/202217/6/2026
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.
ModificadaAlta (7.5)0.89%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1511/7/202217/6/2026
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
ModificadaAlta (7.5)0.89%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1511/7/202217/6/2026
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
ModificadaCrítica (9.3)1.4%—Shackerpanel Project Shackerpanel11/7/202217/6/2026
The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (8.8)20%—Control-webpanel Webpanel7/7/202217/6/2026
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
ModificadaMedia (5.9)2.0%—Control-webpanel Webpanel7/7/202217/6/2026
The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
ModificadaCrítica (9.8)57%—Control-webpanel Webpanel7/7/202217/6/2026
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
ModificadaMedia (5.4)0.64%—Jenkins Extreme Feedback Panel30/6/202217/6/2026
Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaCrítica (9.8)1.3%—Egavilanmedia User Registration AND Login System With Admin Panel2/6/202217/6/2026
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.
ModificadaMedia (5.4)0.49%—PHP Mysql Admin Panel Generator Project PHP Mysql Admin Panel Generator28/4/20229/7/2026
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.
Orbitaley — Vulnerabilidades