Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.9) | 0.86% | 💥 PoC | CpanelAICpanel EmailtrackAI | 9/9/2026 | 10/9/2026 | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component | |
| Aplazada | Media (6.9) | 0.87% | 💥 Exploit | CyberpanelAI | 9/9/2026 | 14/9/2026 | CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory… | |
| Aplazada | Alta (8.7) | 0.58% | — | Pterodactyl PanelAI | 5/9/2026 | 24/9/2026 | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server… | |
| Aplazada | Alta (7.5) | 0.24% | — | Gastromenm WEB PanelAI | 4/9/2026 | 8/9/2026 | Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026. | |
| Aplazada | Media (5.3) | 0.24% | — | OpenpanelAI | 4/9/2026 | 10/9/2026 | Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supply an arbitrary victim dashboardId with their own projectId to read report layouts… | |
| Aplazada | Crítica (9.2) | 0.26% | — | OpenpanelAI | 4/9/2026 | 8/9/2026 | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel server issue requests to internal… | |
| Aplazada | Alta (8.4) | 0.40% | — | OpenpanelAI | 4/9/2026 | 8/9/2026 | OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that execute in the victim's browser on the API… | |
| Aplazada | Alta (8.7) | 0.41% | — | OpenpanelAI | 4/9/2026 | 14/9/2026 | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and cloud metadata endpoints, with small… | |
| Aplazada | Media (5.3) | 0.24% | — | OpenpanelAI | 4/9/2026 | 8/9/2026 | OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId with a victim organization's guessable… | |
| Aplazada | Alta (8.7) | 0.71% | — | OpenpanelAI | 4/9/2026 | 10/9/2026 | OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix objects. Attackers can use the recovered constructor to load Node.js built-ins… | |
| Aplazada | Media (6.9) | 0.50% | — | OpenpanelAI | 4/9/2026 | 8/9/2026 | Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). The endpoint passes a user-supplied url query parameter to fetchWithRedirects() and performs server-side HTTP requests to… | |
| Aplazada | Alta (8.7) | 0.56% | — | FeatherpanelAI | 2/9/2026 | 10/9/2026 | FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access… | |
| Analizada | Alta (8.7) | 0.88% | 💥 PoC | Cpanel | 1/9/2026 | 17/9/2026 | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. | |
| Aplazada | Alta (8.8) | 0.43% | — | Ankara Hosting Site Management PanelAI | 31/8/2026 | 1/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026. | |
| Aplazada | Media (6.1) | 0.40% | 💥 PoC | OpanelAI | 28/8/2026 | 9/9/2026 | Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record | |
| Aplazada | Alta (8.1) | 1.9% | 💥 PoC | Osbil Technology OpanelAI | 28/8/2026 | 9/9/2026 | A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter | |
| Aplazada | Alta (7.5) | 0.63% | — | Fuyaweb Internet AND Informatics Services Architectpanel WEB Admin PanelAI | 21/8/2026 | 26/8/2026 | Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026. | |
| Aplazada | Crítica (9.3) | 0.96% | — | CyberpanelAI | 13/8/2026 | 8/9/2026 | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded… | |
| Aplazada | Media (6.9) | 0.50% | — | CyberpanelAI | 13/8/2026 | 8/9/2026 | CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter in the JSON request body, which is… | |
| Aplazada | Alta (8.7) | 3.3% | — | CyberpanelAI | 10/8/2026 | 8/9/2026 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backup transfer feature that allows authenticated attackers to execute arbitrary OS commands by controlling a remote server's API response. Attackers can inject malicious commands through a crafted… | |
| Aplazada | Alta (8.7) | 0.47% | — | CyberpanelAI | 10/8/2026 | 8/9/2026 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote server address. Attackers can exploit the unverified SSH public key retrieval process… | |
| Aplazada | Alta (7.1) | 0.46% | — | CyberpanelAI | 10/8/2026 | 8/9/2026 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbolic links. Attackers can exploit the application's failure to validate symlinks… | |
| Aplazada | Alta (8.8) | 1.6% | — | 4xmen Pm2panelAI | 10/8/2026 | 3/9/2026 | An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execute arbitrary system commands on the host. The pm2panel.js handler at line 188 passes the unsanitized req.query.id parameter directly to exec('pm2 restart ' + id) without input validation or shell… | |
| Aplazada | Media (5.3) | 0.36% | — | Ehco1996 Django-sspanelAI | 4/8/2026 | 12/8/2026 | A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The vendor was contacted… | |
| Aplazada | Baja (2.1) | 0.32% | — | Chetans9 Core-php-admin-panelAI | 4/8/2026 | 12/8/2026 | A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of the argument filter_col can lead to sql injection. The attack… |