Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.39% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multiple admin controllers enforce permission checks on form display methods but omit equivalent checks on the corresponding write methods, allowing any authenticated user to… | |
| Aplazada | Media (4.8) | 0.27% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability exists in the admin role management interface. In app/Http/Controllers/Admin/RoleController.php, the datatable() method interpolates $role->name and $role->color directly… | |
| Aplazada | Alta (8.7) | 0.45% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the ticket reply notification system. Unsanitized reply content ($newmessage) is stored directly in database notification payloads and later rendered unescaped via… | |
| Aplazada | Crítica (10) | 4.5% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Execution (RCE) because it performs the install.lock check only after including and executing form handler files, leaving… | |
| Aplazada | Media (6.5) | 0.35% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints without authorization checks, allowing any authenticated user to access sensitive administrative data that should be restricted to administrators only. The affected admin… | |
| Aplazada | Media (6.6) | 0.69% | — | CtrlpanelAI | 19/5/2026 | 24/7/2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update endpoint accepted a fully qualified class name directly from user-supplied request input and used it for dynamic static method calls and object instantiation without any allowlist validation,… | |
| Aplazada | Alta (8.1) | 0.44% | — | CtrlpanelAI | 11/2/2025 | 17/6/2026 | CtrlPanel is open-source billing software for hosting providers. Prior to version 1.0, a Cross-Site Scripting (XSS) vulnerability exists in the `TicketsController` and `Moderation/TicketsController` due to insufficient input validation on the `priority` field during ticket creation and unsafe rendering of this field… | |
| Modificada | Baja (3.5) | 0.87% | — | Hashmarkconsulting Controlpanel | 25/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.73% | — | Lpanel | 5/7/2005 | 16/6/2026 | Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to… | |
| Modificada | Media (4.3) | 1.2% | — | Lpanel | 6/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel 1.59 and earlier allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the pid parameter. |