Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1168 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.81%—Egavilanmedia User Registration AND Login System With Admin Panel30/12/20209/7/2026
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the…
ModificadaAlta (7.5)1.1%—Egavilanmedia User Registration AND Login System With Admin Panel30/12/20209/7/2026
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
ModificadaAlta (8.8)0.65%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel26/12/202017/6/2026
A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.
ModificadaCrítica (9.8)4.3%—Egavilanmedia Under Construction Page With Cpanel24/12/202017/6/2026
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
ModificadaMedia (6.1)0.97%—Egavilanmedia User Registration AND Login System With Admin Panel23/12/202017/6/2026
Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.
ModificadaAlta (8)0.57%—Egavilanmedia User Registration & Login System With Admin Panel21/12/20209/7/2026
EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.
ModificadaCrítica (9.8)3.1%—Wago PFC 100 FirmwareWago PFC 200 FirmwareWago Touch Panel 600 Standard FirmwareWago Touch Panel 600 Advanced Firmware+117/12/202017/6/2026
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx),…
ModificadaCrítica (9.1)1.5%—Getkirby KirbyGetkirby Panel8/12/202017/6/2026
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Panel can upload a PHP .phar file and execute it on the server. This vulnerability is critical if you might have potential attackers in your group of authenticated Panel…
ModificadaMedia (5.9)0.57%—Getkirby KirbyGetkirby Panel8/12/202017/6/2026
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulnerability in which the admin panel may be accessed if hosted on a .dev domain. In order to protect new installations on public servers that don't have an admin account for the Panel yet, we block…
ModificadaMedia (6.1)0.64%—Cpanel27/11/202017/6/2026
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
ModificadaMedia (6.5)1.2%—Cpanel27/11/202017/6/2026
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
ModificadaMedia (4.1)0.58%—Cpanel27/11/202017/6/2026
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
ModificadaMedia (6.1)0.64%—Cpanel25/9/202017/6/2026
cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).
ModificadaMedia (6.1)0.64%—Cpanel25/9/202017/6/2026
cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).
ModificadaMedia (6.1)0.64%—Cpanel25/9/202017/6/2026
cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).
ModificadaAlta (7.5)0.87%—Cpanel25/9/202017/6/2026
The email quota cache in cPanel before 90.0.10 allows overwriting of files.
ModificadaMedia (6.1)0.64%—Cpanel25/9/202017/6/2026
cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).
ModificadaMedia (6.1)0.78%—Cpanel25/9/202017/6/2026
cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).
ModificadaAlta (7.5)1.2%—Cpanel25/9/202017/6/2026
cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557).
ModificadaCrítica (9.8)2.5%—Cpanel25/9/202017/6/2026
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
ModificadaAlta (7.5)1.4%—Cpanel25/9/202017/6/2026
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
ModificadaAlta (7.5)1.3%—Cpanel25/9/202017/6/2026
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
ModificadaCrítica (9.8)1.4%—Cpanel25/9/202017/6/2026
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
ModificadaAlta (7.5)1.4%—Cpanel25/9/202017/6/2026
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
ModificadaAlta (7.5)1.3%—Cpanel25/9/202017/6/2026
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).