Vulnerability index

Browse CVEs

74 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webpanel CRITICAL 9.0
CVE-2025-48703 KEVEPSS 100%

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_tota…

Fix: 0.9.8.1205+
Fix from $2,300 2025-09-19
Webpanel CRITICAL 9.8
CVE-2023-42121

Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

Mitigation only
Fix from $2,300 2024-05-03
Webpanel HIGH 8.8
CVE-2023-42123

Control Web Panel mysql_manager Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2024-05-03
Webpanel HIGH 7.8
CVE-2023-42122

Control Web Panel wloggui Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privilege…

Mitigation only
Fix from $1,950 2024-05-03
Webpanel HIGH 8.8
CVE-2023-42120

Control Web Panel dns_zone_editor Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2024-05-03
Webpanel CRITICAL 9.8
CVE-2022-44877 KEVEPSS 100%

login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via s…

Fix: 0.9.8.1147+
Fix from $2,300 2023-01-05
Webpanel CRITICAL 9.8
CVE-2021-45466EPSS 55%

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an aut…

Fix: 0.9.8.1107+
Fix from $2,300 2022-12-26
Webpanel CRITICAL 9.8
CVE-2021-45467EPSS 71%

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to regi…

Fix: 0.9.8.1107+
Fix from $2,300 2022-12-26
Webpanel CRITICAL 9.8
CVE-2022-25046EPSS 56%

A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.

Fix: after 0.9.8.1124
Fix from $2,300 2022-07-07
Webpanel HIGH 8.8
CVE-2022-25048EPSS 19%

Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.

No fix yet
Fix from $1,950 2022-07-07
Webpanel MEDIUM 5.9
CVE-2022-25047

The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.

No fix yet
Fix from $1,600 2022-07-07
Webpanel CRITICAL 9.8
CVE-2021-31316EPSS 13%

The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.

No fix yet
Fix from $2,300 2021-05-18
Webpanel CRITICAL 9.8
CVE-2021-31324EPSS 34%

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

No fix yet
Fix from $2,300 2021-05-18
Webpanel CRITICAL 9.8
CVE-2020-15623EPSS 8%

This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i…

Mitigation only
Fix from $2,300 2020-07-28
Webpanel HIGH 7.5
CVE-2020-15621

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authent…

Mitigation only
Fix from $1,950 2020-07-28
Webpanel HIGH 7.5
CVE-2020-15622

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authent…

Mitigation only
Fix from $1,950 2020-07-28
Webpanel HIGH 7.5
CVE-2020-15624

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authent…

Mitigation only
Fix from $1,950 2020-07-28
Webpanel HIGH 7.5
CVE-2020-15625

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authent…

Mitigation only
Fix from $1,950 2020-07-28
Webpanel HIGH 7.5
CVE-2020-15626

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authent…

Mitigation only
Fix from $1,950 2020-07-28
Webpanel HIGH 7.5
CVE-2020-15627

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authent…

Mitigation only
Fix from $1,950 2020-07-28
Webpanel HIGH 7.5
CVE-2020-15628

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authent…

Mitigation only
Fix from $1,950 2020-07-28
Webpanel CRITICAL 9.8
CVE-2020-15608EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …

Mitigation only
Fix from $2,300 2020-07-28
Webpanel CRITICAL 9.8
CVE-2020-15610EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …

Mitigation only
Fix from $2,300 2020-07-28
Webpanel CRITICAL 9.8
CVE-2020-15611EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …

Mitigation only
Fix from $2,300 2020-07-28
Webpanel CRITICAL 9.8
CVE-2020-15612EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …

Mitigation only
Fix from $2,300 2020-07-28
Webpanel CRITICAL 9.8
CVE-2020-15613EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …

Mitigation only
Fix from $2,300 2020-07-28
Webpanel CRITICAL 9.8
CVE-2020-15614EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …

Mitigation only
Fix from $2,300 2020-07-28
Webpanel CRITICAL 9.8
CVE-2020-15615EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication …

Mitigation only
Fix from $2,300 2020-07-28
Webpanel HIGH 7.5
CVE-2020-15616

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authent…

Mitigation only
Fix from $1,950 2020-07-28
Webpanel HIGH 7.5
CVE-2020-15617

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authent…

Mitigation only
Fix from $1,950 2020-07-28