Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Interworx WEB Control Panel | 27/2/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.13 build 574 allows remote attackers to inject arbitrary web script or HTML via the i parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Webhost-panel Bankoi Webhosting Control Panel | 12/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Verlihub-project Verlihub Control Panel | 22/7/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.html. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Xigla Absolute Control Panel XE | 14/7/2009 | 16/6/2026 | Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Xigla Absolute Control Panel XE | 1/5/2009 | 16/6/2026 | Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1." | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Acutecp Acute Control Panel | 6/4/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the theme_directory parameter to (1) container.php and (2) header.php in themes/. | |
| Modificada | Media (4.3) | 1.3% | — | Xigla Absolute Control Panel XE | 18/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/users.asp in Xigla Absolute Control Panel XE 1.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter and other unspecified parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | 4shared Starsgames Control Panel | 27/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Thecus N5200pro NAS Server Control Panel | 19/2/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a URL in the name parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Easy Hosting Control Panel | 30/11/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the confdir parameter to (1) dbutil.bck.php and (2) dbutil.php in config/. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Verlihub-project Verlihub Control Panel | 9/10/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter. | |
| Modificada | Media (4.3) | 0.52% | — | Webhost Automation Helm WEB Hosting Control Panel | 6/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Helm 3.2.16 allow remote attackers to inject arbitrary web script or HTML via (1) the showOption parameter to domain.asp, or the (2) Folder or (3) StartPath parameter to FileManager.asp. | |
| Modificada | Alta (7.5) | 5.9% | — | Ragnarok Online Control Panel Project Ragnarok Online Control Panel | 5/9/2007 | 16/6/2026 | Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an… | |
| Modificada | Media (4.3) | 1.7% | — | Interworx WEB Control Panel | 29/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Webmaster Level (SiteWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php; and allow remote authenticated users to inject arbitrary web script or HTML via the… | |
| Modificada | Media (4.3) | 2.5% | — | Interworx WEB Control Panel | 29/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Server Admin Level (NodeWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php; and allow remote authenticated users to inject arbitrary web script or HTML via the… | |
| Modificada | Media (6.8) | 1.2% | — | Nicola Asuni ALL IN ONE Control Panel | 19/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably a different vulnerability than CVE-2006-5830. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | ALL IN ONE Control Panel | 18/1/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php,… | |
| Modificada | Alta (7.5) | 1.2% | — | Nicola Asuni ALL IN ONE Control Panel | 13/1/2007 | 16/6/2026 | SQL injection vulnerability in shared/code/cp_functions_downloads.php in Nicola Asuni All In One Control Panel (AIOCP) before 1.3.009 allows remote attackers to execute arbitrary SQL commands via the download_category parameter. | |
| Modificada | Media (6.8) | 1.5% | — | Webhost Automation Helm WEB Hosting Control Panel | 20/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) txtCompanyName, (2) txtEmail, or (3) txtUserAccNum parameter to (a) users.asp, or the (4) setThemeColour parameter to (b) default.asp in the… | |
| Modificada | Media (4.3) | 1.2% | — | Swsoft Plesk Control Panel | 21/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in filemanager/filemanager.php in the control panel in SWsoft Plesk 8.0 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the file parameter. | |
| Modificada | Media (5.8) | 2.5% | 💥 Exploit | Webhost Automation Helm WEB Hosting Control Panel | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Helm Hosting Control Panel | 14/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Jasio.net Ragnarok Online Control Panel | 31/12/2005 | 16/6/2026 | functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a trailing "/login.php" PHP_SELF value, which is not properly handled by the CHECK_AUTH function. | |
| Modificada | Alta (7.5) | 1.2% | — | Webhost Automation Helm Control Panel | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Webhost Automation Helm Control Panel | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field. |