Parallels records
155 published records for vendor parallels.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 12
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor20
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-125 Out-of-bounds Read8
- CWE-129 Improper Validation of Array Index7
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition7
- CWE-255 Credentials Management Errors6
The weakness classes this vendor ships most often: where to look.
CWEAll records
155 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2011-4749No exploit | The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feparallels · parallels plesk panel · CWE-255 | Critical10.0 | — | 2.2% | Dec 16, 2011 |
41Plan | CVE-2011-4739No exploit | The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomplete featuparallels · parallels plesk panel · CWE-255 | Critical10.0 | — | 2.2% | Dec 16, 2011 |
41Plan | CVE-2011-4757No exploit | Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easieparallels · parallels plesk small business panel · CWE-255 | Critical10.0 | — | 2.2% | Dec 16, 2011 |
41Plan | CVE-2011-4730No exploit | The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the autparallels · parallels plesk panel · CWE-255 | Critical10.0 | — | 2.2% | Dec 16, 2011 |
41Plan | CVE-2011-4768No exploit | The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter fparallels · parallels plesk small business panel | Critical10.0 | — | 1.9% | Dec 16, 2011 |
41Plan | CVE-2011-4761No exploit | Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remotparallels · parallels plesk small business panel | Critical10.0 | — | 1.8% | Dec 16, 2011 |
41Plan | CVE-2011-4744No exploit | The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorrect Content-Type headers for certain resources, which might parallels · parallels plesk panel | Critical10.0 | — | 1.8% | Dec 16, 2011 |
41Plan | CVE-2011-4762No exploit | Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers tparallels · parallels plesk small business panel | Critical10.0 | — | 1.8% | Dec 16, 2011 |
41Plan | CVE-2011-4743No exploit | The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Content-Type header's charset parameter for certain resources,parallels · parallels plesk panel | Critical10.0 | — | 1.8% | Dec 16, 2011 |
41Plan | CVE-2011-4732No exploit | The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 omits the Content-Type header's charset parameter for cerparallels · parallels plesk panel | Critical10.0 | — | 1.8% | Dec 16, 2011 |
41Plan | CVE-2011-4733No exploit | The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 sends incorrect Content-Type headers for certain resourceparallels · parallels plesk panel | Critical10.0 | — | 1.8% | Dec 16, 2011 |
41Plan | CVE-2011-4755No exploit | Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which alparallels · parallels plesk small business panel · CWE-20 | Critical10.0 | — | 1.8% | Dec 16, 2011 |
41Plan | CVE-2011-4727No exploit | The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended fparallels · parallels plesk panel · CWE-20 | Critical10.0 | — | 1.8% | Dec 16, 2011 |
40Plan | CVE-2020-15860No exploit | Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution.parallels · remote application server | Critical9.9 | — | 4.0% | Jul 24, 2020 |
40Plan | CVE-2023-45894No exploit | The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a rparallels · remote application server | Critical10.0 | — | 1.2% | Dec 14, 2023 |
40Plan | CVE-2024-6240No exploit | Improper privilege management vulnerability in Parallels Desktopparallels · parallels desktop · CWE-269 | Critical10.0 | — | 0.3% | Jun 21, 2024 |
39Monitor | CVE-2013-4878Proof of concept | The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAliparallels · parallels plesk panel · CWE-264 | High7.5 | — | 31.1% | Jul 18, 2013 |
39Monitor | CVE-2024-34331No exploit | A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted mCWE-269 | Critical9.8 | — | 1.0% | Sep 23, 2024 |
38Monitor | CVE-2007-4009Proof of concept | PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackparallels · confixx · CWE-94 | Critical9.3 | — | 4.3% | Jul 25, 2007 |
38Monitor | CVE-2011-4851No exploit | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete featurparallels · parallels plesk panel · CWE-255 | Critical9.3 | — | 1.9% | Dec 16, 2011 |
37Monitor | CVE-2011-4854No exploit | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Coparallels · parallels plesk panel | Critical9.3 | — | 1.6% | Dec 16, 2011 |
37Monitor | CVE-2011-4856No exploit | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might aparallels · parallels plesk panel | Critical9.3 | — | 1.6% | Dec 16, 2011 |
37Monitor | CVE-2011-4855No exploit | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain resources, parallels · parallels plesk panel | Critical9.3 | — | 1.6% | Dec 16, 2011 |
35Monitor | CVE-2025-31359No exploit | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879).parallels · parallels desktop · CWE-22 | High8.8 | — | 1.1% | Jun 3, 2025 |
35Monitor | CVE-2020-8875No exploit | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123.parallels · parallels desktop · CWE-129 | High8.8 | — | 0.5% | Mar 23, 2020 |
- CVE-2011-474941Plan
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete fe
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2011-473941Plan
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomplete featu
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2011-475741Plan
Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easie
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk small business panelDec 16, 2011
- CVE-2011-473041Plan
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the aut
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2011-476841Plan
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter f
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk small business panelDec 16, 2011
- CVE-2011-476141Plan
Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remot
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk small business panelDec 16, 2011
- CVE-2011-474441Plan
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorrect Content-Type headers for certain resources, which might
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2011-476241Plan
Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers t
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk small business panelDec 16, 2011
- CVE-2011-474341Plan
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Content-Type header's charset parameter for certain resources,
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2011-473241Plan
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 omits the Content-Type header's charset parameter for cer
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2011-473341Plan
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 sends incorrect Content-Type headers for certain resource
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2011-475541Plan
Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which al
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk small business panelDec 16, 2011
- CVE-2011-472741Plan
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended f
CriticalCVSS 10.0No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2020-1586040Plan
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution.
CriticalCVSS 9.9No exploitEPSS 4%parallels · remote application serverJul 24, 2020
- CVE-2023-4589440Plan
The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a r
CriticalCVSS 10.0No exploitEPSS 1%parallels · remote application serverDec 14, 2023
- CVE-2024-624040Plan
Improper privilege management vulnerability in Parallels Desktop
CriticalCVSS 10.0No exploitEPSS 0%parallels · parallels desktopJun 21, 2024
- CVE-2013-487839Monitor
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAli
HighCVSS 7.5Proof of conceptEPSS 31%parallels · parallels plesk panelJul 18, 2013
- CVE-2024-3433139Monitor
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted m
CriticalCVSS 9.8No exploitEPSS 1%Sep 23, 2024
- CVE-2007-400938Monitor
PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attack
CriticalCVSS 9.3Proof of conceptEPSS 4%parallels · confixxJul 25, 2007
- CVE-2011-485138Monitor
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete featur
CriticalCVSS 9.3No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2011-485437Monitor
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Co
CriticalCVSS 9.3No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2011-485637Monitor
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might a
CriticalCVSS 9.3No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2011-485537Monitor
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain resources,
CriticalCVSS 9.3No exploitEPSS 2%parallels · parallels plesk panelDec 16, 2011
- CVE-2025-3135935Monitor
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879).
HighCVSS 8.8No exploitEPSS 1%parallels · parallels desktopJun 3, 2025
- CVE-2020-887535Monitor
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123.
HighCVSS 8.8No exploitEPSS 1%parallels · parallels desktopMar 23, 2020