Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.88%—Aapanel21/5/202517/6/2026
AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.
AnalizadaAlta (7.6)0.42%—Seopanel SEO Panel17/4/202517/6/2026
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
AnalizadaAlta (7.6)0.42%—Seopanel SEO Panel17/4/202517/6/2026
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
AnalizadaMedia (5.9)0.31%—Panelizer (obsolete) Project Panelizer (obsolete)16/4/202517/6/2026
Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.
AplazadaMedia (5.3)0.49%—Mediavine Control PanelAI16/4/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel mediavine-control-panel allows Retrieve Embedded Sensitive Data.This issue affects Mediavine Control Panel: from n/a through <= 2.10.6.
AplazadaCrítica (9.8)0.89%—DpanelAI15/4/202517/6/2026
Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and compromise the host machine. This security flaw allows attackers to analyze the source…
AnalizadaMedia (6.5)0.38%—Drupal Panels9/4/202517/6/2026
Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0.
AnalizadaMedia (5.5)0.18%—Openpanel Openadmin14/3/202517/6/2026
Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function
AnalizadaMedia (5.5)0.27%—Openpanel14/3/202517/6/2026
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
AnalizadaAlta (8)0.46%—Openpanel14/3/202517/6/2026
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
AplazadaCrítica (9.8)0.41%—Merkur Software B2B Login PanelAI5/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2B Login Panel allows SQL Injection. This issue affects B2B Login Panel: before 15.01.2025.
AplazadaMedia (5.5)0.19%—Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAI27/2/202517/6/2026
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux)…
AplazadaCrítica (10)0.51%—BSS Software Mobuy Online Machinery Monitoring PanelAI14/2/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection. This issue affects Mobuy Online Machinery Monitoring Panel: before 2.0.
AplazadaAlta (8.1)0.44%—CtrlpanelAI11/2/202517/6/2026
CtrlPanel is open-source billing software for hosting providers. Prior to version 1.0, a Cross-Site Scripting (XSS) vulnerability exists in the `TicketsController` and `Moderation/TicketsController` due to insufficient input validation on the `priority` field during ticket creation and unsafe rendering of this field…
AplazadaAlta (7.1)0.17%—Digitimber Cpanel IntegrationAI3/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DigiTimber DigiTimber cPanel Integration digitimber-cpanel-integration allows Stored XSS.This issue affects DigiTimber cPanel Integration: from n/a through <= 1.4.6.
AnalizadaCrítica (9.8)4.2%💥 ExploitOpenpanel31/1/202517/6/2026
OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
AnalizadaAlta (7.5)3.3%💥 ExploitOpenpanel31/1/202517/6/2026
An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via a crafted HTTP request.
AnalizadaCrítica (9.1)2.4%💥 ExploitOpenpanel31/1/202517/6/2026
An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.
AplazadaAlta (7.1)0.13%—Operationsissuu Issuu PanelAI31/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in operationsissuu Issuu Panel issuu-panel allows Stored XSS.This issue affects Issuu Panel: from n/a through <= 2.1.1.
AnalizadaAlta (7.1)0.16%—Phycticio DYN Business Panel27/1/202517/6/2026
The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
AnalizadaAlta (7.1)0.33%—Phycticio DYN Business Panel27/1/202517/6/2026
The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaAlta (7.1)0.54%💥 ExploitPhycticio DYN Business Panel27/1/202517/6/2026
The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaAlta (7.5)0.62%—Cyberpower Powerpanel BusinessAI15/1/202517/6/2026
A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. The attacker can repeatedly restart ppbd.exe to render it unavailable.
AnalizadaMedia (5.3)0.54%—Code-projects Simple Admin Panel26/12/202417/6/2026
A vulnerability has been found in code-projects Simple Admin Panel 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file updateOrderStatus.php. The manipulation of the argument record leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (5.3)0.57%—Code-projects Simple Admin Panel26/12/202417/6/2026
A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. Affected is an unknown function of the file addVariationController.php. The manipulation of the argument qty leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
Orbitaley — Vulnerabilidades