Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.45%—Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+810/9/202417/6/2026
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <…
AplazadaMedia (5.9)0.43%—Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+810/9/202417/6/2026
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <…
AplazadaAlta (8.2)0.45%—Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+810/9/202417/6/2026
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <…
AplazadaMedia (6.5)0.26%—Mediavine Control PanelAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mediavine Mediavine Control Panel mediavine-control-panel.This issue affects Mediavine Control Panel: from n/a through <= 2.10.4.
AplazadaAlta (7.1)0.31%—Parcel PanelAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Parcel Panel ParcelPanel allows Reflected XSS.This issue affects ParcelPanel: from n/a through 4.3.2.
AplazadaCrítica (9.9)0.61%—GST Electronics Inohom Nova Panel N7AI12/8/202417/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass. This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it was learned that the product is not supported.
ModificadaCrítica (9.8)4.5%—Fit2cloud 1panel18/7/202417/6/2026
1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version 1.10.12-lts. Users are advised to upgrade. There are no known workarounds for this vulnerability.
ModificadaCrítica (9.8)29%💥 ExploitFit2cloud 1panel18/7/202417/6/2026
1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no…
ModificadaAlta (8.8)4.0%—Mgt-commerce Cloudpanel14/6/202417/6/2026
Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles function.
AnalizadaCrítica (9.8)0.56%—Cyberpower Powerpanel15/5/202417/6/2026
CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.
AnalizadaCrítica (9.8)0.52%—Cyberpower Powerpanel15/5/202417/6/2026
CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.
AplazadaAlta (8.8)0.71%—Cyberpower PowerpanelAI15/5/202417/6/2026
A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution.
AnalizadaCrítica (9.8)0.47%—Cyberpower Powerpanel15/5/202417/6/2026
Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application.
AnalizadaCrítica (9.8)0.51%—Cyberpower Powerpanel15/5/202417/6/2026
Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access to the testing or production server.
AnalizadaAlta (7.5)0.38%—Cyberpower Powerpanel15/5/202417/6/2026
The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing the passwords to be recovered.
AnalizadaAlta (8.8)0.53%—Cyberpower Powerpanel15/5/202417/6/2026
An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code.
AnalizadaMedia (6.5)0.20%—Cyberpower Powerpanel15/5/202417/6/2026
The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to impersonate any client in the system and send malicious data.
ModificadaAlta (7.5)0.35%—Cyberpower Powerpanel15/5/202417/6/2026
Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.
AnalizadaAlta (7.5)1.3%—Fit2cloud 1panel14/5/202417/6/2026
1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol `>` can be used to…
AnalizadaAlta (7.5)5.4%💥 ExploitCyberpower Powerpanel14/5/202417/6/2026
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.
AnalizadaAlta (7.5)4.6%💥 ExploitCyberpower Powerpanel14/5/202417/6/2026
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lean" function within MCUDBHelper.
AnalizadaAlta (7.5)5.4%💥 ExploitCyberpower Powerpanel14/5/202417/6/2026
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper.
AnalizadaAlta (7.5)5.4%💥 ExploitCyberpower Powerpanel14/5/202417/6/2026
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.
AnalizadaCrítica (9.8)6.8%💥 ExploitCyberpower Powerpanel14/5/202417/6/2026
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.
AplazadaAlta (8.5)0.52%—Parcel PanelAI6/5/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1.