Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.45% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Aplazada | Media (5.9) | 0.43% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Aplazada | Alta (8.2) | 0.45% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Aplazada | Media (6.5) | 0.26% | — | Mediavine Control PanelAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mediavine Mediavine Control Panel mediavine-control-panel.This issue affects Mediavine Control Panel: from n/a through <= 2.10.4. | |
| Aplazada | Alta (7.1) | 0.31% | — | Parcel PanelAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Parcel Panel ParcelPanel allows Reflected XSS.This issue affects ParcelPanel: from n/a through 4.3.2. | |
| Aplazada | Crítica (9.9) | 0.61% | — | GST Electronics Inohom Nova Panel N7AI | 12/8/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass. This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Modificada | Crítica (9.8) | 4.5% | — | Fit2cloud 1panel | 18/7/2024 | 17/6/2026 | 1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version 1.10.12-lts. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Modificada | Crítica (9.8) | 29% | 💥 Exploit | Fit2cloud 1panel | 18/7/2024 | 17/6/2026 | 1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no… | |
| Modificada | Alta (8.8) | 4.0% | — | Mgt-commerce Cloudpanel | 14/6/2024 | 17/6/2026 | Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles function. | |
| Analizada | Crítica (9.8) | 0.56% | — | Cyberpower Powerpanel | 15/5/2024 | 17/6/2026 | CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges. | |
| Analizada | Crítica (9.8) | 0.52% | — | Cyberpower Powerpanel | 15/5/2024 | 17/6/2026 | CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication. | |
| Aplazada | Alta (8.8) | 0.71% | — | Cyberpower PowerpanelAI | 15/5/2024 | 17/6/2026 | A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 0.47% | — | Cyberpower Powerpanel | 15/5/2024 | 17/6/2026 | Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application. | |
| Analizada | Crítica (9.8) | 0.51% | — | Cyberpower Powerpanel | 15/5/2024 | 17/6/2026 | Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access to the testing or production server. | |
| Analizada | Alta (7.5) | 0.38% | — | Cyberpower Powerpanel | 15/5/2024 | 17/6/2026 | The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing the passwords to be recovered. | |
| Analizada | Alta (8.8) | 0.53% | — | Cyberpower Powerpanel | 15/5/2024 | 17/6/2026 | An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code. | |
| Analizada | Media (6.5) | 0.20% | — | Cyberpower Powerpanel | 15/5/2024 | 17/6/2026 | The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to impersonate any client in the system and send malicious data. | |
| Modificada | Alta (7.5) | 0.35% | — | Cyberpower Powerpanel | 15/5/2024 | 17/6/2026 | Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device. | |
| Analizada | Alta (7.5) | 1.3% | — | Fit2cloud 1panel | 14/5/2024 | 17/6/2026 | 1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol `>` can be used to… | |
| Analizada | Alta (7.5) | 5.4% | 💥 Exploit | Cyberpower Powerpanel | 14/5/2024 | 17/6/2026 | A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper. | |
| Analizada | Alta (7.5) | 4.6% | 💥 Exploit | Cyberpower Powerpanel | 14/5/2024 | 17/6/2026 | A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lean" function within MCUDBHelper. | |
| Analizada | Alta (7.5) | 5.4% | 💥 Exploit | Cyberpower Powerpanel | 14/5/2024 | 17/6/2026 | A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper. | |
| Analizada | Alta (7.5) | 5.4% | 💥 Exploit | Cyberpower Powerpanel | 14/5/2024 | 17/6/2026 | A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper. | |
| Analizada | Crítica (9.8) | 6.8% | 💥 Exploit | Cyberpower Powerpanel | 14/5/2024 | 17/6/2026 | An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application. | |
| Aplazada | Alta (8.5) | 0.52% | — | Parcel PanelAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1. |