Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1168 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.97%—Siemens Simatic HMI Comfort Outdoor Panels 7" FirmwareSiemens Simatic HMI Comfort Outdoor Panels 15" FirmwareSiemens Simatic HMI Comfort Panels 4" FirmwareSiemens Simatic HMI Comfort Panels 22" Firmware+612/5/202117/6/2026
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)…
ModificadaMedia (5.3)1.0%—Siemens Simatic HMI KTP Mobile Panels FirmwareSiemens Simatic HMI Comfort Panels Firmware12/5/202117/6/2026
A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 4). Specially crafted packets sent to port 161/udp can cause the SNMP service of affected devices to crash. A manual restart…
ModificadaAlta (7.3)1.1%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+183/5/202117/6/2026
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
ModificadaMedia (6.1)0.58%—Cpanel26/4/202117/6/2026
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
ModificadaAlta (7.8)0.50%—Vestacp Control Panel8/4/202117/6/2026
VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a /reset/?action=confirm&user=admin&code= URI. This occurs…
ModificadaAlta (7.2)1.8%—Vestacp Vesta Control Panel8/4/202117/6/2026
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.
ModificadaMedia (4.8)0.76%—Seopanel SEO Panel25/3/202117/6/2026
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type" parameter.
ModificadaMedia (4.8)0.83%—Seopanel SEO Panel25/3/202117/6/2026
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter.
ModificadaMedia (4.8)0.76%—Seopanel SEO Panel25/3/202117/6/2026
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.php in the "to_time" parameter.
ModificadaMedia (5.9)64%💥 PoCOpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaAlta (7.5)3.2%—Lldpd Project LldpdOpenvswitchRedhat Openshift Container PlatformRedhat Openstack+1318/3/202117/6/2026
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
ModificadaMedia (4.8)1.9%💥 ExploitSeopanel SEO Panel18/3/202117/6/2026
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.
ModificadaAlta (7.2)11%💥 ExploitSeopanel SEO Panel18/3/202117/6/2026
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.
ModificadaMedia (4.8)1.9%💥 ExploitSeopanel SEO Panel18/3/202117/6/2026
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.
ModificadaMedia (4.8)1.9%💥 ExploitSeopanel SEO Panel18/3/202117/6/2026
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.
ModificadaAlta (8.8)6.0%💥 ExploitMyvestacp MyvestaVestacp Vesta Control Panel15/3/202117/6/2026
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
ModificadaCrítica (9.8)1.7%—Bittacora Bpanel2/3/202117/6/2026
In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL injections, which could lead to platform compromise.
ModificadaMedia (5.4)1.4%—Hestiacp Control Panel16/2/202117/6/2026
Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.
ModificadaCrítica (9.8)5.2%—Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI KTP Mobile Panels FirmwareSiemens Sinamics Gh150 FirmwareSiemens Sinamics Gl150 Firmware+69/2/202117/6/2026
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions),…
ModificadaAlta (7.5)0.92%—Cpanel26/1/202117/6/2026
cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).
ModificadaAlta (7.5)0.92%—Cpanel26/1/202117/6/2026
cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).
ModificadaCrítica (9.8)2.5%—Egavilanmedia User Registration AND Login System With Admin Panel26/1/202117/6/2026
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
ModificadaMedia (6.1)4.3%💥 ExploitSeopanel SEO Panel1/1/202117/6/2026
Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.
ModificadaMedia (5.4)0.52%—Seopanel SEO Panel31/12/202017/6/2026
Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI.
ModificadaMedia (5.4)0.60%—Egavilanmedia User Registration AND Login System With Admin Panel30/12/20209/7/2026
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers.