Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2888▼ 169 respecto a la semana anterior
Críticas / altas1285▼ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.40%—OpanelAI28/8/20269/9/2026
Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record
AplazadaAlta (8.1)1.9%—Osbil Technology OpanelAI28/8/20269/9/2026
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter
AplazadaAlta (7)0.26%—Seopanel SEO PanelAI21/1/202617/6/2026
SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL…
AnalizadaAlta (7.6)0.42%—Seopanel SEO Panel17/4/202517/6/2026
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
AnalizadaAlta (7.6)0.42%—Seopanel SEO Panel17/4/202517/6/2026
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
ModificadaMedia (5.3)0.61%—Seopanel SEO Panel30/1/202417/6/2026
A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment.
ModificadaMedia (5.3)0.56%—Seopanel SEO Panel30/1/202417/6/2026
An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames.
ModificadaMedia (5.3)0.58%—Seopanel SEO Panel30/1/202417/6/2026
An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system.
ModificadaMedia (6.5)0.33%—Seopanel SEO Panel30/1/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets.
ModificadaAlta (7.5)0.94%—Seopanel SEO Panel15/2/202317/6/2026
SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information.
ModificadaMedia (6.1)0.84%—Seopanel SEO Panel5/11/202117/6/2026
Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, and (j) reports.php; the (2) from_time…
ModificadaAlta (8.8)3.7%—Seopanel20/8/202117/6/2026
A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function.
ModificadaMedia (4.8)0.76%—Seopanel SEO Panel25/3/202117/6/2026
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type" parameter.
ModificadaMedia (4.8)0.83%—Seopanel SEO Panel25/3/202117/6/2026
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter.
ModificadaMedia (4.8)0.76%—Seopanel SEO Panel25/3/202117/6/2026
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.php in the "to_time" parameter.
ModificadaMedia (4.8)1.9%—Seopanel SEO Panel18/3/202117/6/2026
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.
ModificadaAlta (7.2)11%—Seopanel SEO Panel18/3/202117/6/2026
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.
ModificadaMedia (4.8)1.9%—Seopanel SEO Panel18/3/202117/6/2026
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.
ModificadaMedia (4.8)1.9%—Seopanel SEO Panel18/3/202117/6/2026
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.
ModificadaMedia (6.1)4.3%—Seopanel SEO Panel1/1/202117/6/2026
Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.
ModificadaMedia (5.4)0.52%—Seopanel SEO Panel31/12/202017/6/2026
Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI.
ModificadaMedia (4.8)0.79%—Seopanel SEO Panel2/3/202017/6/2026
The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or HTML via the websites.php name parameter.
ModificadaAlta (8.8)1.1%—Seopanel SEO Panel29/8/201717/6/2026
SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.1)0.71%—Seopanel SEO Panel29/8/201717/6/2026
Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.2%—Seopanel SEO Panel13/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in Seo Panel before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.