Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | — | Siemens Simatic HMI Comfort Outdoor Panels 7" FirmwareSiemens Simatic HMI Comfort Outdoor Panels 15" FirmwareSiemens Simatic HMI Comfort Panels 4" FirmwareSiemens Simatic HMI Comfort Panels 22" Firmware+6 | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)… | |
| Modificada | Media (5.3) | 1.0% | — | Siemens Simatic HMI KTP Mobile Panels FirmwareSiemens Simatic HMI Comfort Panels Firmware | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 4). Specially crafted packets sent to port 161/udp can cause the SNMP service of affected devices to crash. A manual restart… | |
| Modificada | Alta (7.3) | 1.1% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+18 | 3/5/2021 | 17/6/2026 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages. | |
| Modificada | Media (6.1) | 0.58% | — | Cpanel | 26/4/2021 | 17/6/2026 | cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581). | |
| Modificada | Alta (7.8) | 0.50% | — | Vestacp Control Panel | 8/4/2021 | 17/6/2026 | VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a /reset/?action=confirm&user=admin&code= URI. This occurs… | |
| Modificada | Alta (7.2) | 1.8% | — | Vestacp Vesta Control Panel | 8/4/2021 | 17/6/2026 | VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts. | |
| Modificada | Media (4.8) | 0.76% | — | Seopanel SEO Panel | 25/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type" parameter. | |
| Modificada | Media (4.8) | 0.83% | — | Seopanel SEO Panel | 25/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter. | |
| Modificada | Media (4.8) | 0.76% | — | Seopanel SEO Panel | 25/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.php in the "to_time" parameter. | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Alta (7.5) | 3.2% | — | Lldpd Project LldpdOpenvswitchRedhat Openshift Container PlatformRedhat Openstack+13 | 18/3/2021 | 17/6/2026 | A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability. | |
| Modificada | Media (4.8) | 1.9% | 💥 Exploit | Seopanel SEO Panel | 18/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter. | |
| Modificada | Alta (7.2) | 11% | 💥 Exploit | Seopanel SEO Panel | 18/3/2021 | 17/6/2026 | The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases. | |
| Modificada | Media (4.8) | 1.9% | 💥 Exploit | Seopanel SEO Panel | 18/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter. | |
| Modificada | Media (4.8) | 1.9% | 💥 Exploit | Seopanel SEO Panel | 18/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter. | |
| Modificada | Alta (8.8) | 6.0% | 💥 Exploit | Myvestacp MyvestaVestacp Vesta Control Panel | 15/3/2021 | 17/6/2026 | web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin. | |
| Modificada | Crítica (9.8) | 1.7% | — | Bittacora Bpanel | 2/3/2021 | 17/6/2026 | In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL injections, which could lead to platform compromise. | |
| Modificada | Media (5.4) | 1.4% | — | Hestiacp Control Panel | 16/2/2021 | 17/6/2026 | Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages. | |
| Modificada | Crítica (9.8) | 5.2% | — | Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI KTP Mobile Panels FirmwareSiemens Sinamics Gh150 FirmwareSiemens Sinamics Gl150 Firmware+6 | 9/2/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions),… | |
| Modificada | Alta (7.5) | 0.92% | — | Cpanel | 26/1/2021 | 17/6/2026 | cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579). | |
| Modificada | Alta (7.5) | 0.92% | — | Cpanel | 26/1/2021 | 17/6/2026 | cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578). | |
| Modificada | Crítica (9.8) | 2.5% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 26/1/2021 | 17/6/2026 | EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution. | |
| Modificada | Media (6.1) | 4.3% | 💥 Exploit | Seopanel SEO Panel | 1/1/2021 | 17/6/2026 | Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter. | |
| Modificada | Media (5.4) | 0.52% | — | Seopanel SEO Panel | 31/12/2020 | 17/6/2026 | Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI. | |
| Modificada | Media (5.4) | 0.60% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 30/12/2020 | 9/7/2026 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers. |