Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.35% | — | Qrmenumpro Menu Panel | 29/1/2026 | 17/6/2026 | Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affects Menu Panel: through 29012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Modificada | Crítica (9.8) | 0.37% | — | Qrmenumpro Menu Panel | 29/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Exploitation of Trusted Identifiers. This issue affects Menu Panel: through 29012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Media (5.3) | 0.39% | — | Cloudpanel CLP Varnish CacheAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in CloudPanel CLP Varnish Cache clp-varnish-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CLP Varnish Cache: from n/a through <= 1.0.2. | |
| Aplazada | Alta (7) | 0.26% | — | Seopanel SEO PanelAI | 21/1/2026 | 17/6/2026 | SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL… | |
| Aplazada | Alta (8.6) | 0.49% | — | Hestia Control PanelAI | 21/1/2026 | 17/6/2026 | Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to write SSH keys or other content to specific file paths on the server. | |
| Analizada | Media (6) | 0.24% | — | Pterodactyl Panel | 19/1/2026 | 17/6/2026 | Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. These resource limits are applied on a per-server basis, and validated during the… | |
| Analizada | Alta (8.4) | 0.36% | — | Fit2cloud 1panel | 18/1/2026 | 17/6/2026 | 1Panel is an open-source, web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) vulnerability exists in the 1Panel App Store when viewing application details. Malicious scripts can execute in the context of the user’s browser, potentially compromising session data or sensitive system… | |
| Analizada | Alta (8.1) | 0.66% | — | Dpanel | 15/1/2026 | 17/6/2026 | DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/delete interface. Authenticated users can delete arbitrary files on the server via path traversal. When a user logs into the administrative backend, this… | |
| Aplazada | Alta (8.6) | 2.4% | — | Algo 8028 Control PanelAI | 13/1/2026 | 17/6/2026 | Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code… | |
| Analizada | Media (6.5) | 0.36% | — | Pterodactyl Panel | 6/1/2026 | 7/10/2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during sign-in, and afterward it is not sufficiently marked as used in the system. This allows an attacker… | |
| Analizada | Alta (7.5) | 0.37% | — | Pterodactyl PanelPterodactyl Wings | 6/1/2026 | 7/10/2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain… | |
| Aplazada | Baja (2) | 0.22% | — | Cloudpanel Community EditionAI | 30/12/2025 | 7/10/2026 | A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such manipulation of the argument Referer leads to open redirect. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (6.1) | 0.19% | 💥 PoC | Machsol Machpanel | 29/12/2025 | 17/6/2026 | Stored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF file. | |
| Analizada | Crítica (9.8) | 0.43% | 💥 PoC | Machsol Machpanel | 29/12/2025 | 7/10/2026 | File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell. | |
| Analizada | Alta (8.8) | 0.83% | — | Cpanel | 11/12/2025 | 17/6/2026 | An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user. | |
| Analizada | Media (5.1) | 0.21% | — | Fit2cloud 1panel | 10/12/2025 | 14/7/2026 | 1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name management functionality. The affected endpoint does not implement CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a panel-name… | |
| Analizada | Alta (7) | 0.18% | — | Fit2cloud 1panel | 10/12/2025 | 14/7/2026 | 1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality. The port-change endpoint lacks CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a port-change request; when… | |
| Analizada | Alta (7) | 0.16% | — | Fit2cloud 1panel | 10/12/2025 | 14/7/2026 | 1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the settings panel (/settings/panel). The endpoint does not implement CSRF protections such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious… | |
| Analizada | Media (6.5) | 0.25% | — | Fit2cloud 1panel | 9/12/2025 | 17/6/2026 | 1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.14 and below use Gin's default configuration which trusts all IP addresses as proxies (TrustedProxies = 0.0.0.0/0), allowing any client to spoof the X-Forwarded-For header. Since all IP-based access controls (AllowIPs, API… | |
| Analizada | Alta (7.5) | 0.47% | — | Fit2cloud 1panel | 9/12/2025 | 17/6/2026 | 1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previously trusted this value without proper validation, CAPTCHA protections can be… | |
| Analizada | Alta (7.5) | 0.39% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+13 | 1/12/2025 | 17/6/2026 | An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition. | |
| Aplazada | Media (4.3) | 0.22% | — | Download PanelAI | 18/11/2025 | 17/6/2026 | The Download Panel plugin for WordPress is vulnerable to unauthorized settings modification due to a missing capability check on the 'wp_ajax_save_settings' AJAX action in all versions up to, and including, 1.3.3. This is due to the absence of any capability verification in the `dlpn_save_settings()` function. This… | |
| Aplazada | Baja (2) | 0.25% | — | Aapanel BaotaAI | 8/11/2025 | 17/6/2026 | A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /database?action=GetDatabaseAccess of the component Backend. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.8) | 1.2% | — | Magdesign Pocketvj Control Panel Firmware | 5/11/2025 | 17/6/2026 | PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote attackers to execute arbitrary commands… | |
| Aplazada | Alta (7.5) | 0.61% | — | Woocommerce Category AND Products Accordion PanelAI | 15/10/2025 | 17/6/2026 | The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the 'categoryaccordionpanel' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute… |