Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.34% | — | Teknolojik Center Telecommunication Industry Trade CO LTD B2B Netsis PanelAI | 3/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center Telecommunication Industry Trade Co. Ltd. B2B - Netsis Panel allows SQL Injection. This issue affects B2B - Netsis Panel: through 20251003. NOTE: The vendor was contacted early about this disclosure… | |
| Analizada | Media (6.5) | 0.34% | — | Magdesign Pocketvj Control Panel Firmware | 23/9/2025 | 17/6/2026 | An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Control-webpanel Webpanel | 19/9/2025 | 17/6/2026 | CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known. | |
| Analizada | Alta (8.8) | 1.2% | — | Fit2cloud 1panel | 10/9/2025 | 17/6/2026 | OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /api/v2/hosts/ssh/operate endpoint. | |
| Aplazada | Media (5.8) | 0.28% | — | Solax CloudAISolax Solarpanel InverterAI | 10/9/2025 | 17/6/2026 | A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known. | |
| Aplazada | Media (5.6) | 0.44% | — | Cpanel Json XSAI | 8/9/2025 | 17/6/2026 | Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact | |
| Aplazada | Crítica (9.8) | 0.45% | 💥 PoC | SMM PanelAI | 25/8/2025 | 17/6/2026 | SQL Injection vulnerability in SMM Panel 3.1 allowing remote attackers to gain sensitive information via a crafted HTTP request with action=service_detail. | |
| Analizada | Media (6.1) | 0.29% | — | Ehcp Easy Hosting Control Panel | 22/8/2025 | 17/6/2026 | Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template parameter. | |
| Analizada | Media (6.1) | 0.24% | — | Ehcp Easy Hosting Control Panel | 22/8/2025 | 17/6/2026 | Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter. | |
| Aplazada | Media (4.8) | 0.46% | — | DpanelAI | 22/8/2025 | 17/6/2026 | dpanel is an open source server management panel written in Go. In versions 1.2.0 through 1.7.2, dpanel allows authenticated users to read arbitrary files from the server via the /api/app/compose/get-from-uri API endpoint. The vulnerability exists in the GetFromUri function in… | |
| Modificada | Media (5.4) | 0.23% | — | Ehcp Easy Hosting Control Panel | 21/8/2025 | 17/6/2026 | SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter. | |
| Analizada | Media (6.5) | 0.26% | — | Ehcp Easy Hosting Control Panel | 19/8/2025 | 17/6/2026 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function. | |
| Analizada | Alta (7.5) | 0.81% | 💥 PoC | Microsoft Dynamics 365 GuidesMicrosoft Dynamics 365 Remote AssistMicrosoft TeamsMicrosoft Teams Panels+1 | 12/8/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (4.8) | 0.24% | — | Ehcp Easy Hosting Control Panel | 8/8/2025 | 17/6/2026 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function. | |
| Analizada | Media (6.3) | 0.20% | — | Ehcp Easy Hosting Control Panel | 8/8/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter. | |
| Aplazada | Alta (7.7) | 0.64% | — | RatpanelAIGo-chi CHIAI | 5/8/2025 | 17/6/2026 | RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obtains the backend login path of RatPanel (including but not limited to weak default paths, brute-force cracking, etc.), they can execute system commands or take over hosts managed by the panel without… | |
| Aplazada | Alta (8.5) | 0.32% | 💥 Exploit | ZpanelAI | 4/8/2025 | 16/6/2026 | ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured in /etc/sudoers, zsudo can be invoked by low-privileged users to execute arbitrary commands as root. This flaw enables local attackers with shell access to escalate… | |
| Analizada | Crítica (9.8) | 0.94% | 💥 PoC | Fit2cloud 1panel | 1/8/2025 | 17/6/2026 | 1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below, the HTTPS protocol used for communication between the Core and Agent endpoints has incomplete certificate verification during certificate validation, leading to… | |
| Aplazada | Alta (8.7) | 1.6% | 💥 Exploit | ZpanelAI | 1/8/2025 | 16/6/2026 | A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htaccess files, the inHTUsername field is passed unsanitized to a system() call that invokes the system’s htpasswd binary. By injecting shell metacharacters into the username field, an authenticated… | |
| Aplazada | Alta (8.8) | 0.39% | — | Aapanel WP ToolkitAI | 18/7/2025 | 17/6/2026 | The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versions 1.0 to 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass all role checks and gain full admin… | |
| Aplazada | Media (6.8) | 0.19% | — | ABB Lite Panel PROAI | 30/6/2025 | 17/6/2026 | Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1. | |
| Aplazada | Crítica (10) | 1.8% | — | Convoypanel ConvoyAI | 23/6/2025 | 17/6/2026 | Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a directory traversal vulnerability in the LocaleController component of Performave Convoy. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted HTTP request with… | |
| Aplazada | Media (4.3) | 0.14% | — | WP Sliding Login Dashboard PanelAI | 13/6/2025 | 17/6/2026 | The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the wp_sliding_panel_user_options() function. This makes it possible for unauthenticated attackers to update plugin… | |
| Aplazada | Crítica (9.3) | 0.73% | — | Cs5000 Fire PanelAIVNC ServerAI | 30/5/2025 | 17/6/2026 | The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for running VNC. This password cannot be altered, allowing anyone with knowledge of it to gain remote access to the panel. Such access could enable an attacker to operate the… | |
| Aplazada | Crítica (9.3) | 0.73% | — | Cs5000 Fire PanelAI | 30/5/2025 | 17/6/2026 | The CS5000 Fire Panel is vulnerable due to a default account that exists on the panel. Even though it is possible to change this by SSHing into the device, it has remained unchanged on every installed system observed. This account is not root but holds high-level permissions that could severely impact the device's… |