Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)4.5%—Hestiacp Control Panel28/4/202217/6/2026
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
ModificadaAlta (7.5)1.5%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+147/4/202217/6/2026
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
ModificadaMedia (6.5)0.61%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+67/4/202217/6/2026
A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.
ModificadaAlta (7.5)1.3%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+167/4/202217/6/2026
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
ModificadaAlta (8.1)1.1%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+147/4/202217/6/2026
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
ModificadaAlta (7.1)0.89%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+167/4/202217/6/2026
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed,…
ModificadaMedia (6.5)1.0%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+167/4/202217/6/2026
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
ModificadaAlta (8.8)1.8%—Wpanel CMS Project Wpanel CMS31/3/202217/6/2026
Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.
ModificadaMedia (6.5)1.8%—Aapanel27/3/202217/6/2026
aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa).
ModificadaMedia (6.1)0.87%—Hestiacp Control Panel16/3/202217/6/2026
Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.
ModificadaMedia (6.1)0.97%—Hestiacp Control Panel4/3/202217/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.
ModificadaMedia (6.1)1.1%—Hestiacp Control Panel4/3/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.
ModificadaMedia (6.1)0.83%—Hestiacp Control Panel3/3/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.
ModificadaMedia (6.1)0.64%—Zerodream Sakurapanel2/12/202117/6/2026
SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit function will terminate the script and print the message $data['proxy_name'].
ModificadaCrítica (9.8)1.2%—Vestacp Vesta Control Panel29/11/202117/6/2026
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
ModificadaMedia (4.3)0.39%—Pterodactyl Panel17/11/202117/6/2026
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node auto-deployment token. At no point…
ModificadaAlta (8.8)2.4%—Opengamepanel10/11/202117/6/2026
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command.
ModificadaAlta (8.8)1.4%—Opengamepanel10/11/202117/6/2026
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.
ModificadaMedia (6.1)0.84%—Seopanel SEO Panel5/11/202117/6/2026
Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, and (j) reports.php; the (2) from_time…
ModificadaMedia (4.3)0.52%—Pterodactyl Panel25/10/202117/6/2026
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This requires a targeted attack against a…
ModificadaMedia (6.1)0.74%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel22/10/202117/6/2026
Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields.
ModificadaAlta (8.1)1.8%—Pterodactyl Panel6/10/202117/6/2026
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to reference a cache value not associated with the login attempt. In rare cases this can allow a malicious…
ModificadaMedia (6.1)9.9%💥 ExploitHkurl I-panel Administration System4/10/202117/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable malicious button.
ModificadaCrítica (9.8)1.1%—Hestiacp Control Panel15/9/202117/6/2026
hestiacp is vulnerable to Use of Wrong Operator in String Comparison
ModificadaAlta (8.8)3.7%—Seopanel20/8/202117/6/2026
A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function.