Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 4.5% | — | Hestiacp Control Panel | 28/4/2022 | 17/6/2026 | Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context. | |
| Modificada | Alta (7.5) | 1.5% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+14 | 7/4/2022 | 17/6/2026 | A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system. | |
| Modificada | Media (6.5) | 0.61% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+6 | 7/4/2022 | 17/6/2026 | A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy. | |
| Modificada | Alta (7.5) | 1.3% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+16 | 7/4/2022 | 17/6/2026 | An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed. | |
| Modificada | Alta (8.1) | 1.1% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+14 | 7/4/2022 | 17/6/2026 | A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. | |
| Modificada | Alta (7.1) | 0.89% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+16 | 7/4/2022 | 17/6/2026 | An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed,… | |
| Modificada | Media (6.5) | 1.0% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+16 | 7/4/2022 | 17/6/2026 | An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash. | |
| Modificada | Alta (8.8) | 1.8% | — | Wpanel CMS Project Wpanel CMS | 31/3/2022 | 17/6/2026 | Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image. | |
| Modificada | Media (6.5) | 1.8% | — | Aapanel | 27/3/2022 | 17/6/2026 | aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa). | |
| Modificada | Media (6.1) | 0.87% | — | Hestiacp Control Panel | 16/3/2022 | 17/6/2026 | Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11. | |
| Modificada | Media (6.1) | 0.97% | — | Hestiacp Control Panel | 4/3/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9. | |
| Modificada | Media (6.1) | 1.1% | — | Hestiacp Control Panel | 4/3/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10. | |
| Modificada | Media (6.1) | 0.83% | — | Hestiacp Control Panel | 3/3/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9. | |
| Modificada | Media (6.1) | 0.64% | — | Zerodream Sakurapanel | 2/12/2021 | 17/6/2026 | SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit function will terminate the script and print the message $data['proxy_name']. | |
| Modificada | Crítica (9.8) | 1.2% | — | Vestacp Vesta Control Panel | 29/11/2021 | 17/6/2026 | vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php. | |
| Modificada | Media (4.3) | 0.39% | — | Pterodactyl Panel | 17/11/2021 | 17/6/2026 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node auto-deployment token. At no point… | |
| Modificada | Alta (8.8) | 2.4% | — | Opengamepanel | 10/11/2021 | 17/6/2026 | An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command. | |
| Modificada | Alta (8.8) | 1.4% | — | Opengamepanel | 10/11/2021 | 17/6/2026 | An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext. | |
| Modificada | Media (6.1) | 0.84% | — | Seopanel SEO Panel | 5/11/2021 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, and (j) reports.php; the (2) from_time… | |
| Modificada | Media (4.3) | 0.52% | — | Pterodactyl Panel | 25/10/2021 | 17/6/2026 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This requires a targeted attack against a… | |
| Modificada | Media (6.1) | 0.74% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 22/10/2021 | 17/6/2026 | Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields. | |
| Modificada | Alta (8.1) | 1.8% | — | Pterodactyl Panel | 6/10/2021 | 17/6/2026 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to reference a cache value not associated with the login attempt. In rare cases this can allow a malicious… | |
| Modificada | Media (6.1) | 9.9% | 💥 Exploit | Hkurl I-panel Administration System | 4/10/2021 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable malicious button. | |
| Modificada | Crítica (9.8) | 1.1% | — | Hestiacp Control Panel | 15/9/2021 | 17/6/2026 | hestiacp is vulnerable to Use of Wrong Operator in String Comparison | |
| Modificada | Alta (8.8) | 3.7% | — | Seopanel | 20/8/2021 | 17/6/2026 | A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function. |