Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.45% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the ticket reply notification system. Unsanitized reply content ($newmessage) is stored directly in database notification payloads and later rendered unescaped via… | |
| Aplazada | Crítica (10) | 4.5% | 💥 Exploit | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Execution (RCE) because it performs the install.lock check only after including and executing form handler files, leaving… | |
| Aplazada | Media (6.5) | 0.35% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints without authorization checks, allowing any authenticated user to access sensitive administrative data that should be restricted to administrators only. The affected admin… | |
| Aplazada | Media (6.6) | 0.69% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update endpoint accepted a fully qualified class name directly from user-supplied request input and used it for dynamic static method calls and object instantiation without any allowlist validation,… | |
| Analizada | Alta (8.2) | 0.32% | — | CpanelCpanel WP SquaredCpanel WHM | 13/5/2026 | 12/8/2026 | SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. | |
| Analizada | Alta (8.6) | 0.41% | — | CpanelCpanel WP SquaredCpanel WHM | 13/5/2026 | 12/8/2026 | Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. | |
| Analizada | Alta (8.2) | 0.49% | — | Schneider-electric Ecostruxure Panel Server Pas400 FirmwareSchneider-electric Ecostruxure Panel Server Pas600 FirmwareSchneider-electric Ecostruxure Panel Server Pas600v2 FirmwareSchneider-electric Ecostruxure Panel Server Pas800 Firmware+1 | 12/5/2026 | 24/6/2026 | CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials. | |
| Pendiente de análisis | Alta (8.7) | 0.53% | — | CyberpanelAI | 10/5/2026 | 6/10/2026 | CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the completeStartingPath parameter in POST requests to… | |
| Pendiente de análisis | Media (5.3) | 0.52% | — | Cpanel Nova PluginAI | 8/5/2026 | 17/6/2026 | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home… | |
| Pendiente de análisis | Alta (7.3) | 3.6% | 💥 Exploit | Control WEB PanelAISoftaculousAISitepadAI | 8/5/2026 | 17/6/2026 | An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated attackers to inject and execute… | |
| Analizada | Crítica (9.3) | 99% | ⚠ Explotación activa💥 Exploit | CpanelCpanel WHMCpanel WP Squared | 29/4/2026 | 30/9/2026 | cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. | |
| Modificada | Alta (8.8) | 1.1% | 💥 PoC | Cyberpanel | 24/4/2026 | 11/8/2026 | CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can… | |
| Modificada | Media (5.3) | 0.64% | 💥 PoC | Cyberpanel | 24/4/2026 | 11/8/2026 | CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records.… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Crítica (9.8) | 0.39% | — | Convoypanel Convoy | 2/4/2026 | 24/7/2026 | Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did not verify the cryptographic signature of JWT tokens. While the method configured a symmetric HMAC-SHA256 signer via lcobucci/jwt, it only validated time-based claims… | |
| Analizada | Baja (2) | 0.34% | — | Xiaopi Panel | 2/4/2026 | 17/6/2026 | A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the argument param leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.… | |
| Modificada | Crítica (9.8) | 0.78% | — | Aapanel | 18/3/2026 | 17/6/2026 | An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Analizada | Alta (7.5) | 0.43% | — | Aapanel | 18/3/2026 | 17/6/2026 | A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensitive information exposure. | |
| Analizada | Alta (7.5) | 0.52% | — | Aapanel | 18/3/2026 | 17/6/2026 | An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression Denial of Service (ReDoS) via a crafted input. | |
| Analizada | Media (5.4) | 0.26% | — | Ekacnet Grafanacubism-panel | 11/3/2026 | 17/6/2026 | The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor privileges can set the link to a javascript:… | |
| Analizada | Crítica (9.2) | 0.46% | — | Pterodactyl Panel | 19/2/2026 | 17/6/2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node secret token to fetch information about any server on a Pterodactyl instance, even if that server is… | |
| Aplazada | Crítica (9.8) | 0.41% | — | NTN Information Processing Services Computer Software Hardware Industry AND Trade Smart PanelAI | 12/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Smart Panel: before 20251215. | |
| Aplazada | Media (6.9) | 0.84% | — | Jung Smart Panel KNXAI | 10/2/2026 | 17/6/2026 | JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the embedded web interface. The application fails to properly validate file path input, allowing remote, unauthenticated attackers to access arbitrary files on the underlying filesystem within the… | |
| Analizada | Baja (2.1) | 0.31% | — | Xiaopi Panel | 8/2/2026 | 17/6/2026 | A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.php of the component WAF Firewall. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Alta (7.5) | 0.70% | — | Chetans9 Core-php-admin-panelAI | 3/2/2026 | 17/6/2026 | chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass vulnerability in includes/auth_validate.php. The application sends an HTTP redirect via header(Location:login.php) when a user is not authenticated but fails to call exit() afterward. This allows remote unauthenticated attackers… |