Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9) | 0.40% | — | Cpanel WHMAI | 2/10/2026 | 2/10/2026 | There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface. | |
| Aplazada | Crítica (9) | 0.40% | — | Cpanel WHMAI | 2/10/2026 | 2/10/2026 | There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface. | |
| Aplazada | Baja (2) | 0.20% | — | Aapanel BaotaAI | 28/9/2026 | 28/9/2026 | A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain Handler. The manipulation of the argument get results in sql injection. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2) | 0.25% | — | AapanelAI | 28/9/2026 | 28/9/2026 | A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the argument log_type leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.… | |
| Aplazada | Alta (8.5) | 1.8% | — | Aapanel BaotaAI | 28/9/2026 | 1/10/2026 | A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed… | |
| Aplazada | Alta (8.5) | 2.3% | — | Aapanel BaotaAI | 28/9/2026 | 28/9/2026 | A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Alta (8.5) | 1.8% | — | Aapanel BaotaAI | 28/9/2026 | 28/9/2026 | A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to… | |
| Pendiente de análisis | Crítica (9.4) | 0.61% | — | WP ToolkitAICpanelAI | 23/9/2026 | 24/9/2026 | Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts. | |
| Pendiente de análisis | Crítica (9.4) | 0.58% | — | CpanelAI | 23/9/2026 | 24/9/2026 | Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges. | |
| Aplazada | Media (6.5) | 0.48% | — | CyberpanelAI | 23/9/2026 | 25/9/2026 | CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply absolute or otherwise out-of-scope file paths in the listOfFiles JSON property, together with… | |
| Aplazada | Media (6.5) | 0.54% | — | CyberpanelAI | 23/9/2026 | 24/9/2026 | CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply an arbitrary absolute or out-of-scope path in the fileName JSON property. Because authorization validates… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Openpanel Js-runtimeAI | 19/9/2026 | 2/10/2026 | OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and… | |
| Aplazada | Media (6.9) | 0.41% | — | Openpanel Tracking APIAI | 19/9/2026 | 2/10/2026 | OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters. | |
| Aplazada | Media (5.3) | 0.33% | — | OpenpanelAIClickhouseAI | 19/9/2026 | 2/10/2026 | OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects. | |
| Aplazada | Media (4.8) | 0.17% | — | OpenpanelAI | 19/9/2026 | 2/10/2026 | OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encoded credentials to replay MCP requests and access project analytics. | |
| Aplazada | Alta (7.1) | 0.46% | — | Convoypanel ConvoyAI | 18/9/2026 | 24/9/2026 | Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() and fetches the Source only by sourceID without confirming that its ProjectID… | |
| Aplazada | Alta (8.7) | 0.65% | — | Pelican Project Pelican PanelAI | 16/9/2026 | 24/9/2026 | Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify startup commands, docker images, and… | |
| Aplazada | Media (4.3) | 0.28% | — | CyberpanelAI | 13/9/2026 | 16/9/2026 | CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list. | |
| Aplazada | Alta (7.7) | 0.34% | — | CyberpanelAI | 13/9/2026 | 16/9/2026 | CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement. | |
| Aplazada | Media (4.3) | 0.31% | — | CyberpanelAI | 13/9/2026 | 16/9/2026 | CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic. | |
| Aplazada | Alta (8.6) | 0.65% | — | CyberpanelAI | 10/9/2026 | 11/9/2026 | CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the… | |
| Aplazada | Alta (8.7) | 0.43% | — | OpenpanelAI | 10/9/2026 | 2/10/2026 | OpenPanel through 2.3.0 share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names, filters, and breakdown… | |
| Aplazada | Media (5.3) | 0.28% | — | OpenpanelAI | 10/9/2026 | 2/10/2026 | In OpenPanel through 2.3.0, the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/safe-fetch.ts). In packages/importer/src/providers/umami.ts, parseRemoteFile calls fetch() on config.fileUrl, which is validated only by z.string().url(), so… | |
| Aplazada | Alta (7.2) | 0.37% | — | OpenpanelAI | 10/9/2026 | 2/10/2026 | OpenPanel through 2.3.0 fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics… | |
| Aplazada | Alta (8.4) | 0.39% | — | OpenpanelAI | 10/9/2026 | 2/10/2026 | OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary… |