Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

1167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.45%—CtrlpanelAI19/5/202624/7/2026
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the ticket reply notification system. Unsanitized reply content ($newmessage) is stored directly in database notification payloads and later rendered unescaped via…
AplazadaCrítica (10)4.5%💥 ExploitCtrlpanelAI19/5/202624/7/2026
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Execution (RCE) because it performs the install.lock check only after including and executing form handler files, leaving…
AplazadaMedia (6.5)0.35%—CtrlpanelAI19/5/202624/7/2026
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints without authorization checks, allowing any authenticated user to access sensitive administrative data that should be restricted to administrators only. The affected admin…
AplazadaMedia (6.6)0.69%—CtrlpanelAI19/5/202624/7/2026
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update endpoint accepted a fully qualified class name directly from user-supplied request input and used it for dynamic static method calls and object instantiation without any allowlist validation,…
AnalizadaAlta (8.2)0.32%—CpanelCpanel WP SquaredCpanel WHM13/5/202612/8/2026
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
AnalizadaAlta (8.6)0.41%—CpanelCpanel WP SquaredCpanel WHM13/5/202612/8/2026
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
AnalizadaAlta (8.2)0.49%—Schneider-electric Ecostruxure Panel Server Pas400 FirmwareSchneider-electric Ecostruxure Panel Server Pas600 FirmwareSchneider-electric Ecostruxure Panel Server Pas600v2 FirmwareSchneider-electric Ecostruxure Panel Server Pas800 Firmware+112/5/202624/6/2026
CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.
Pendiente de análisisAlta (8.7)0.53%—CyberpanelAI10/5/20266/10/2026
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the completeStartingPath parameter in POST requests to…
Pendiente de análisisMedia (5.3)0.52%—Cpanel Nova PluginAI8/5/202617/6/2026
A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home…
Pendiente de análisisAlta (7.3)3.6%💥 ExploitControl WEB PanelAISoftaculousAISitepadAI8/5/202617/6/2026
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated attackers to inject and execute…
AnalizadaCrítica (9.3)99%⚠ Explotación activa💥 ExploitCpanelCpanel WHMCpanel WP Squared29/4/202630/9/2026
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
ModificadaAlta (8.8)1.1%💥 PoCCyberpanel24/4/202611/8/2026
CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can…
ModificadaMedia (5.3)0.64%💥 PoCCyberpanel24/4/202611/8/2026
CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records.…
AnalizadaAlta (7.8)3.4%⚠ Explotación activa💥 ExploitLinux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+4422/4/20268/9/2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different…
AnalizadaCrítica (9.8)0.39%—Convoypanel Convoy2/4/202624/7/2026
Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did not verify the cryptographic signature of JWT tokens. While the method configured a symmetric HMAC-SHA256 signer via lcobucci/jwt, it only validated time-based claims…
AnalizadaBaja (2)0.34%—Xiaopi Panel2/4/202617/6/2026
A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the argument param leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.…
ModificadaCrítica (9.8)0.78%—Aapanel18/3/202617/6/2026
An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.
AnalizadaAlta (7.5)0.43%—Aapanel18/3/202617/6/2026
A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensitive information exposure.
AnalizadaAlta (7.5)0.52%—Aapanel18/3/202617/6/2026
An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression Denial of Service (ReDoS) via a crafted input.
AnalizadaMedia (5.4)0.26%—Ekacnet Grafanacubism-panel11/3/202617/6/2026
The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor privileges can set the link to a javascript:…
AnalizadaCrítica (9.2)0.46%—Pterodactyl Panel19/2/202617/6/2026
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node secret token to fetch information about any server on a Pterodactyl instance, even if that server is…
AplazadaCrítica (9.8)0.41%—NTN Information Processing Services Computer Software Hardware Industry AND Trade Smart PanelAI12/2/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Smart Panel: before 20251215.
AplazadaMedia (6.9)0.84%—Jung Smart Panel KNXAI10/2/202617/6/2026
JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the embedded web interface. The application fails to properly validate file path input, allowing remote, unauthenticated attackers to access arbitrary files on the underlying filesystem within the…
AnalizadaBaja (2.1)0.31%—Xiaopi Panel8/2/202617/6/2026
A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.php of the component WAF Firewall. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for…
AplazadaAlta (7.5)0.70%—Chetans9 Core-php-admin-panelAI3/2/202617/6/2026
chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass vulnerability in includes/auth_validate.php. The application sends an HTTP redirect via header(Location:login.php) when a user is not authenticated but fails to call exit() afterward. This allows remote unauthenticated attackers…