Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-29859 An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file. Aapanel Mitigation only Fix from $2,3002026-03-18 HIGH 7.5 CVE-2026-29856 An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression Denial of Servi… Aapanel No fix yet Fix from $1,9502026-03-18 HIGH 7.5 CVE-2026-29858 A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensitive information exposure. Aapanel No fix yet Fix from $1,9502026-03-18 MEDIUM 6.5 CVE-2024-42922 AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability. Aapanel after 7.0.7 Fix from $1,6002025-05-21 MEDIUM 6.5 CVE-2022-26252 aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(i… Aapanel No fix yet Fix from $1,6002022-03-27 HIGH 8.8 CVE-2021-37840 aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a ws:// URL for /webssh (the v… Aapanel after 6.8.12 Fix from $1,9502021-08-02 HIGH 8.8 CVE-2020-14950 aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a modified /system?action=ServiceAd… Aapanel after 6.6.6 Fix from $1,9502020-06-21 HIGH 7.2 CVE-2020-14421EPSS 6% aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen. Aapanel after 6.6.6 Fix from $1,9502020-06-18