Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.4) | 0.56% | 💥 PoC | CpanelAI | 31/7/2026 | 3/9/2026 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | |
| Pendiente de análisis | Media (5.6) | 0.52% | — | CpanelAI | 31/7/2026 | 3/9/2026 | HTTP Smuggling in cPanel allows potential leak of credentials. | |
| Aplazada | Alta (8.2) | 0.44% | — | FTC Software IT Services FTC E-commerce Management PanelAI | 30/7/2026 | 30/7/2026 | Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2. | |
| Aplazada | Alta (8.1) | 0.68% | — | Pterodactyl PanelAIPterodactyl WingsAI | 28/7/2026 | 30/7/2026 | Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel… | |
| Aplazada | Alta (8.7) | 0.51% | — | CyberpanelAI | 23/7/2026 | 27/7/2026 | CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate other tenants' backup… | |
| Aplazada | Alta (7.2) | 0.49% | — | CyberpanelAI | 23/7/2026 | 23/7/2026 | CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName… | |
| Aplazada | Media (4.3) | 0.25% | — | Mediavine Control PanelAI | 23/7/2026 | 23/7/2026 | Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | |
| Aplazada | Baja (2.1) | 0.37% | — | 1panel-dev CordyscrmAI | 19/7/2026 | 21/7/2026 | A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java of the component Third Party Edit Endpoint. Executing a manipulation of the argument appSecret can lead to… | |
| Aplazada | Baja (2.1) | 0.37% | — | 1panel-dev CordyscrmAI | 19/7/2026 | 20/7/2026 | A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint. Performing a manipulation of the argument mkAddress results in server-side… | |
| Pendiente de análisis | Crítica (9.3) | 0.88% | — | Themis NetpanelAI | 13/7/2026 | 14/7/2026 | Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated attackers to upload arbitrary PHP files by providing a base64-encoded payload and to execute arbitrary code on the underlying… | |
| Analizada | Media (5.1) | 0.30% | — | Hestiacp Control Panel | 10/7/2026 | 29/9/2026 | HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply htmlspecialchars() encoding to the DNS record… | |
| Analizada | Alta (8.7) | 3.2% | — | Hestiacp Control Panel | 10/7/2026 | 29/9/2026 | HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient input validation in… | |
| Pendiente de análisis | Crítica (9.3) | 0.96% | 💥 PoC | Control WEB PanelAIRoundcubeAI | 1/7/2026 | 2/7/2026 | Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection… | |
| Aplazada | Media (6.5) | 0.44% | — | Control Panel Client Portal PROAI | 17/6/2026 | 17/6/2026 | CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions. | |
| Analizada | Alta (8.5) | 0.81% | ⚠ Explotación activa💥 PoC | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 14/6/2026 | 23/7/2026 | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026. | |
| Pendiente de análisis | Crítica (9.9) | 0.74% | — | Cpanel Wordpress ToolkitAI | 12/6/2026 | 17/6/2026 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account. | |
| Analizada | Alta (7.5) | 0.62% | — | Rurban Cpanel\ | 3/6/2026 | 22/7/2026 | Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When… | |
| Analizada | Alta (7.3) | 0.41% | — | Rurban Cpanel\ | 3/6/2026 | 21/7/2026 | Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE (old_value) != SVt_RV && SvTYPE (SvRV… | |
| Aplazada | Baja (2) | 0.24% | — | 1panel-dev CordyscrmAI | 2/6/2026 | 22/7/2026 | A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. This impacts the function Save of the file src/main/java/cn/cordys/crm/system/service/ModuleFormService.java of the component ModuleFormController. The manipulation of the argument Description leads to cross site scripting. The attack may… | |
| Aplazada | Baja (1.9) | 0.25% | — | 1panel-dev CordyscrmAI | 2/6/2026 | 22/7/2026 | A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to… | |
| Aplazada | Media (6.3) | 0.13% | 💥 PoC | Jason2605 AdminpanelAI | 27/5/2026 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0. | |
| Aplazada | Alta (8.3) | 0.28% | — | Kenik Camera Management PanelAIKenik Kg-5260xxxx-il- G 2AI | 25/5/2026 | 23/7/2026 | Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file path and read corresponding files located on the server. The issue was fixed in version 2026-04-23 of the KG-5260xxxx-IL-(G)2 cameras. Rest of the products were fixed in… | |
| Analizada | Crítica (10) | 1.0% | ⚠ Explotación activa💥 PoC | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 21/5/2026 | 23/7/2026 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been… | |
| Aplazada | Alta (8.1) | 0.39% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multiple admin controllers enforce permission checks on form display methods but omit equivalent checks on the corresponding write methods, allowing any authenticated user to… | |
| Aplazada | Media (4.8) | 0.27% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability exists in the admin role management interface. In app/Http/Controllers/Admin/RoleController.php, the datatable() method interpolates $role->name and $role->color directly… |