« Volver al listado

Control-webpanel

Control-webpanel Webpanel: vulnerabilidades y CVE

Control-webpanel Webpanel tiene 85 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 37 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE85
Últimos 12 meses0
Críticas37
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-48703Crítica (9)100%⚠ Explotación activa19 sept 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root…
CVE-2022-44877Crítica (9.8)100%⚠ Explotación activa5 ene 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-48703Crítica (9)100%⚠ Explotación activa19 sept 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root…
CVE-2023-42123Alta (8.8)2.3%—3 may 2024
Control Web Panel mysql_manager Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication…
CVE-2023-42122Alta (7.8)0.77%—3 may 2024
Control Web Panel wloggui Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Control Web Panel. An attacker must…
CVE-2023-42121Crítica (9.8)1.8%—3 may 2024
Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not…
CVE-2023-42120Alta (8.8)2.6%—3 may 2024
Control Web Panel dns_zone_editor Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel.…
CVE-2022-44877Crítica (9.8)100%⚠ Explotación activa5 ene 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
CVE-2021-45467Crítica (9.8)71%—26 dic 2022
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a…
CVE-2021-45466Crítica (9.8)55%—26 dic 2022
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.
CVE-2022-25048Alta (8.8)20%—7 jul 2022
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
CVE-2022-25047Media (5.9)2.0%—7 jul 2022
The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
CVE-2022-25046Crítica (9.8)57%—7 jul 2022
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
CVE-2021-31324Crítica (9.8)35%—18 may 2021
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.
CVE-2021-31316Crítica (9.8)13%—18 may 2021
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.
CVE-2020-15628Alta (7.5)3.8%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15627Alta (7.5)3.8%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15626Alta (7.5)3.8%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15625Alta (7.5)3.8%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15624Alta (7.5)4.0%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15623Crítica (9.8)8.3%—28 jul 2020
This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists…
CVE-2020-15622Alta (7.5)3.8%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15621Alta (7.5)3.8%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15620Alta (7.5)4.0%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15619Alta (7.5)3.8%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15618Alta (7.5)3.8%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15617Alta (7.5)3.8%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15616Alta (7.5)4.0%—28 jul 2020
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific…
CVE-2020-15615Crítica (9.8)8.1%—28 jul 2020
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw…
CVE-2020-15614Crítica (9.8)8.1%—28 jul 2020
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw…
CVE-2020-15613Crítica (9.8)8.1%—28 jul 2020
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw…
CVE-2020-15612Crítica (9.8)8.4%—28 jul 2020
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1190 Exploit Public-Facing Application2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.