Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.1%—Interworx WEB Control Panel27/2/201417/6/2026
Cross-site scripting (XSS) vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.13 build 574 allows remote attackers to inject arbitrary web script or HTML via the i parameter.
ModificadaAlta (7.5)0.97%💥 ExploitWebhost-panel Bankoi Webhosting Control Panel12/8/200916/6/2026
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
ModificadaMedia (4.3)1.8%💥 ExploitVerlihub-project Verlihub Control Panel22/7/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.html.
ModificadaAlta (7.5)2.5%💥 ExploitXigla Absolute Control Panel XE14/7/200916/6/2026
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
ModificadaAlta (7.5)2.4%💥 ExploitXigla Absolute Control Panel XE1/5/200916/6/2026
Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1."
ModificadaAlta (7.5)2.5%💥 ExploitAcutecp Acute Control Panel6/4/200916/6/2026
Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the theme_directory parameter to (1) container.php and (2) header.php in themes/.
ModificadaMedia (4.3)1.3%—Xigla Absolute Control Panel XE18/6/200816/6/2026
Cross-site scripting (XSS) vulnerability in admin/users.asp in Xigla Absolute Control Panel XE 1.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter and other unspecified parameters. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.5%💥 Exploit4shared Starsgames Control Panel27/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter.
ModificadaMedia (6.8)2.0%💥 ExploitThecus N5200pro NAS Server Control Panel19/2/200816/6/2026
PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a URL in the name parameter.
ModificadaAlta (7.5)2.4%💥 ExploitEasy Hosting Control Panel30/11/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the confdir parameter to (1) dbutil.bck.php and (2) dbutil.php in config/.
ModificadaMedia (6.8)2.3%💥 ExploitVerlihub-project Verlihub Control Panel9/10/200716/6/2026
Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter.
ModificadaMedia (4.3)0.52%—Webhost Automation Helm WEB Hosting Control Panel6/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Helm 3.2.16 allow remote attackers to inject arbitrary web script or HTML via (1) the showOption parameter to domain.asp, or the (2) Folder or (3) StartPath parameter to FileManager.asp.
ModificadaAlta (7.5)5.9%—Ragnarok Online Control Panel Project Ragnarok Online Control Panel5/9/200716/6/2026
Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an…
ModificadaMedia (4.3)1.7%—Interworx WEB Control Panel29/8/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Webmaster Level (SiteWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php; and allow remote authenticated users to inject arbitrary web script or HTML via the…
ModificadaMedia (4.3)2.5%—Interworx WEB Control Panel29/8/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Server Admin Level (NodeWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php; and allow remote authenticated users to inject arbitrary web script or HTML via the…
ModificadaMedia (6.8)1.2%—Nicola Asuni ALL IN ONE Control Panel19/1/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably a different vulnerability than CVE-2006-5830.
ModificadaAlta (7.5)2.0%💥 ExploitALL IN ONE Control Panel18/1/200716/6/2026
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php,…
ModificadaAlta (7.5)1.2%—Nicola Asuni ALL IN ONE Control Panel13/1/200716/6/2026
SQL injection vulnerability in shared/code/cp_functions_downloads.php in Nicola Asuni All In One Control Panel (AIOCP) before 1.3.009 allows remote attackers to execute arbitrary SQL commands via the download_category parameter.
ModificadaMedia (6.8)1.5%—Webhost Automation Helm WEB Hosting Control Panel20/11/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) txtCompanyName, (2) txtEmail, or (3) txtUserAccNum parameter to (a) users.asp, or the (4) setThemeColour parameter to (b) default.asp in the…
ModificadaMedia (4.3)1.2%—Swsoft Plesk Control Panel21/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in filemanager/filemanager.php in the control panel in SWsoft Plesk 8.0 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the file parameter.
ModificadaMedia (5.8)2.5%💥 ExploitWebhost Automation Helm WEB Hosting Control Panel28/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.
ModificadaMedia (4.3)1.9%💥 ExploitHelm Hosting Control Panel14/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.
ModificadaAlta (7.5)1.5%—Jasio.net Ragnarok Online Control Panel31/12/200516/6/2026
functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a trailing "/login.php" PHP_SELF value, which is not properly handled by the CHECK_AUTH function.
ModificadaAlta (7.5)1.2%—Webhost Automation Helm Control Panel31/12/200416/6/2026
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
ModificadaMedia (4.3)1.8%💥 ExploitWebhost Automation Helm Control Panel31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
Orbitaley — Vulnerabilidades