Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

1167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9)0.40%—Cpanel WHMAI2/10/20262/10/2026
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
AplazadaCrítica (9)0.40%—Cpanel WHMAI2/10/20262/10/2026
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
AplazadaBaja (2)0.20%—Aapanel BaotaAI28/9/202628/9/2026
A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain Handler. The manipulation of the argument get results in sql injection. It is possible to launch the attack remotely. The…
AplazadaBaja (2)0.25%—AapanelAI28/9/202628/9/2026
A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the argument log_type leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.…
AplazadaAlta (8.5)1.8%—Aapanel BaotaAI28/9/20261/10/2026
A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed…
AplazadaAlta (8.5)2.3%—Aapanel BaotaAI28/9/202628/9/2026
A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely.…
AplazadaAlta (8.5)1.8%—Aapanel BaotaAI28/9/202628/9/2026
A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to…
Pendiente de análisisCrítica (9.4)0.61%—WP ToolkitAICpanelAI23/9/202624/9/2026
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Pendiente de análisisCrítica (9.4)0.58%—CpanelAI23/9/202624/9/2026
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
AplazadaMedia (6.5)0.48%—CyberpanelAI23/9/202625/9/2026
CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply absolute or otherwise out-of-scope file paths in the listOfFiles JSON property, together with…
AplazadaMedia (6.5)0.54%—CyberpanelAI23/9/202624/9/2026
CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply an arbitrary absolute or out-of-scope path in the fileName JSON property. Because authorization validates…
AplazadaCrítica (9.4)0.67%—Openpanel Js-runtimeAI19/9/20262/10/2026
OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and…
AplazadaMedia (6.9)0.41%—Openpanel Tracking APIAI19/9/20262/10/2026
OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.
AplazadaMedia (5.3)0.33%—OpenpanelAIClickhouseAI19/9/20262/10/2026
OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.
AplazadaMedia (4.8)0.17%—OpenpanelAI19/9/20262/10/2026
OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encoded credentials to replay MCP requests and access project analytics.
AplazadaAlta (7.1)0.46%—Convoypanel ConvoyAI18/9/202624/9/2026
Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() and fetches the Source only by sourceID without confirming that its ProjectID…
AplazadaAlta (8.7)0.65%—Pelican Project Pelican PanelAI16/9/202624/9/2026
Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify startup commands, docker images, and…
AplazadaMedia (4.3)0.28%—CyberpanelAI13/9/202616/9/2026
CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
AplazadaAlta (7.7)0.34%—CyberpanelAI13/9/202616/9/2026
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
AplazadaMedia (4.3)0.31%—CyberpanelAI13/9/202616/9/2026
CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.
AplazadaAlta (8.6)0.65%—CyberpanelAI10/9/202611/9/2026
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the…
AplazadaAlta (8.7)0.43%—OpenpanelAI10/9/20262/10/2026
OpenPanel through 2.3.0 share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names, filters, and breakdown…
AplazadaMedia (5.3)0.28%—OpenpanelAI10/9/20262/10/2026
In OpenPanel through 2.3.0, the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/safe-fetch.ts). In packages/importer/src/providers/umami.ts, parseRemoteFile calls fetch() on config.fileUrl, which is validated only by z.string().url(), so…
AplazadaAlta (7.2)0.37%—OpenpanelAI10/9/20262/10/2026
OpenPanel through 2.3.0 fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics…
AplazadaAlta (8.4)0.39%—OpenpanelAI10/9/20262/10/2026
OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary…