Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.88% | — | Aapanel | 21/5/2025 | 17/6/2026 | AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability. | |
| Analizada | Alta (7.6) | 0.42% | — | Seopanel SEO Panel | 17/4/2025 | 17/6/2026 | An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component. | |
| Analizada | Alta (7.6) | 0.42% | — | Seopanel SEO Panel | 17/4/2025 | 17/6/2026 | An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component. | |
| Analizada | Media (5.9) | 0.31% | — | Panelizer (obsolete) Project Panelizer (obsolete) | 16/4/2025 | 17/6/2026 | Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*. | |
| Aplazada | Media (5.3) | 0.49% | — | Mediavine Control PanelAI | 16/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel mediavine-control-panel allows Retrieve Embedded Sensitive Data.This issue affects Mediavine Control Panel: from n/a through <= 2.10.6. | |
| Aplazada | Crítica (9.8) | 0.89% | — | DpanelAI | 15/4/2025 | 17/6/2026 | Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and compromise the host machine. This security flaw allows attackers to analyze the source… | |
| Analizada | Media (6.5) | 0.38% | — | Drupal Panels | 9/4/2025 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0. | |
| Analizada | Media (5.5) | 0.18% | — | Openpanel Openadmin | 14/3/2025 | 17/6/2026 | Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function | |
| Analizada | Media (5.5) | 0.27% | — | Openpanel | 14/3/2025 | 17/6/2026 | An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function | |
| Analizada | Alta (8) | 0.46% | — | Openpanel | 14/3/2025 | 17/6/2026 | An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function | |
| Aplazada | Crítica (9.8) | 0.41% | — | Merkur Software B2B Login PanelAI | 5/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2B Login Panel allows SQL Injection. This issue affects B2B Login Panel: before 15.01.2025. | |
| Aplazada | Media (5.5) | 0.19% | — | Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAI | 27/2/2025 | 17/6/2026 | Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux)… | |
| Aplazada | Crítica (10) | 0.51% | — | BSS Software Mobuy Online Machinery Monitoring PanelAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection. This issue affects Mobuy Online Machinery Monitoring Panel: before 2.0. | |
| Aplazada | Alta (8.1) | 0.44% | — | CtrlpanelAI | 11/2/2025 | 17/6/2026 | CtrlPanel is open-source billing software for hosting providers. Prior to version 1.0, a Cross-Site Scripting (XSS) vulnerability exists in the `TicketsController` and `Moderation/TicketsController` due to insufficient input validation on the `priority` field during ticket creation and unsafe rendering of this field… | |
| Aplazada | Alta (7.1) | 0.17% | — | Digitimber Cpanel IntegrationAI | 3/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DigiTimber DigiTimber cPanel Integration digitimber-cpanel-integration allows Stored XSS.This issue affects DigiTimber cPanel Integration: from n/a through <= 1.4.6. | |
| Analizada | Crítica (9.8) | 4.2% | 💥 Exploit | Openpanel | 31/1/2025 | 17/6/2026 | OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter. | |
| Analizada | Alta (7.5) | 3.3% | 💥 Exploit | Openpanel | 31/1/2025 | 17/6/2026 | An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via a crafted HTTP request. | |
| Analizada | Crítica (9.1) | 2.4% | 💥 Exploit | Openpanel | 31/1/2025 | 17/6/2026 | An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager. | |
| Aplazada | Alta (7.1) | 0.13% | — | Operationsissuu Issuu PanelAI | 31/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in operationsissuu Issuu Panel issuu-panel allows Stored XSS.This issue affects Issuu Panel: from n/a through <= 2.1.1. | |
| Analizada | Alta (7.1) | 0.16% | — | Phycticio DYN Business Panel | 27/1/2025 | 17/6/2026 | The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Analizada | Alta (7.1) | 0.33% | — | Phycticio DYN Business Panel | 27/1/2025 | 17/6/2026 | The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Alta (7.1) | 0.54% | 💥 Exploit | Phycticio DYN Business Panel | 27/1/2025 | 17/6/2026 | The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.5) | 0.62% | — | Cyberpower Powerpanel BusinessAI | 15/1/2025 | 17/6/2026 | A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. The attacker can repeatedly restart ppbd.exe to render it unavailable. | |
| Analizada | Media (5.3) | 0.54% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability has been found in code-projects Simple Admin Panel 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file updateOrderStatus.php. The manipulation of the argument record leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. Affected is an unknown function of the file addVariationController.php. The manipulation of the argument qty leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… |