Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2888▼ 169 respecto a la semana anterior
Críticas / altas1285▼ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.40% | — | OpanelAI | 28/8/2026 | 9/9/2026 | Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record | |
| Aplazada | Alta (8.1) | 1.9% | — | Osbil Technology OpanelAI | 28/8/2026 | 9/9/2026 | A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter | |
| Aplazada | Alta (7) | 0.26% | — | Seopanel SEO PanelAI | 21/1/2026 | 17/6/2026 | SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL… | |
| Analizada | Alta (7.6) | 0.42% | — | Seopanel SEO Panel | 17/4/2025 | 17/6/2026 | An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component. | |
| Analizada | Alta (7.6) | 0.42% | — | Seopanel SEO Panel | 17/4/2025 | 17/6/2026 | An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component. | |
| Modificada | Media (5.3) | 0.61% | — | Seopanel SEO Panel | 30/1/2024 | 17/6/2026 | A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment. | |
| Modificada | Media (5.3) | 0.56% | — | Seopanel SEO Panel | 30/1/2024 | 17/6/2026 | An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames. | |
| Modificada | Media (5.3) | 0.58% | — | Seopanel SEO Panel | 30/1/2024 | 17/6/2026 | An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system. | |
| Modificada | Media (6.5) | 0.33% | — | Seopanel SEO Panel | 30/1/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets. | |
| Modificada | Alta (7.5) | 0.94% | — | Seopanel SEO Panel | 15/2/2023 | 17/6/2026 | SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information. | |
| Modificada | Media (6.1) | 0.84% | — | Seopanel SEO Panel | 5/11/2021 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, and (j) reports.php; the (2) from_time… | |
| Modificada | Alta (8.8) | 3.7% | — | Seopanel | 20/8/2021 | 17/6/2026 | A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function. | |
| Modificada | Media (4.8) | 0.76% | — | Seopanel SEO Panel | 25/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type" parameter. | |
| Modificada | Media (4.8) | 0.83% | — | Seopanel SEO Panel | 25/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter. | |
| Modificada | Media (4.8) | 0.76% | — | Seopanel SEO Panel | 25/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.php in the "to_time" parameter. | |
| Modificada | Media (4.8) | 1.9% | — | Seopanel SEO Panel | 18/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter. | |
| Modificada | Alta (7.2) | 11% | — | Seopanel SEO Panel | 18/3/2021 | 17/6/2026 | The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases. | |
| Modificada | Media (4.8) | 1.9% | — | Seopanel SEO Panel | 18/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter. | |
| Modificada | Media (4.8) | 1.9% | — | Seopanel SEO Panel | 18/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter. | |
| Modificada | Media (6.1) | 4.3% | — | Seopanel SEO Panel | 1/1/2021 | 17/6/2026 | Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter. | |
| Modificada | Media (5.4) | 0.52% | — | Seopanel SEO Panel | 31/12/2020 | 17/6/2026 | Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI. | |
| Modificada | Media (4.8) | 0.79% | — | Seopanel SEO Panel | 2/3/2020 | 17/6/2026 | The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or HTML via the websites.php name parameter. | |
| Modificada | Alta (8.8) | 1.1% | — | Seopanel SEO Panel | 29/8/2017 | 17/6/2026 | SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.1) | 0.71% | — | Seopanel SEO Panel | 29/8/2017 | 17/6/2026 | Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Seopanel SEO Panel | 13/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Seo Panel before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |