Skip to content
Noroxi

Parallels records

155 published records for vendor parallels.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
12
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

155 records
  • The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete fe

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomplete featu

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easie

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk small business panelDec 16, 2011

  • The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the aut

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter f

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk small business panelDec 16, 2011

  • Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remot

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk small business panelDec 16, 2011

  • The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorrect Content-Type headers for certain resources, which might

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers t

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk small business panelDec 16, 2011

  • The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Content-Type header's charset parameter for certain resources,

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 omits the Content-Type header's charset parameter for cer

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 sends incorrect Content-Type headers for certain resource

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which al

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk small business panelDec 16, 2011

  • The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended f

    CriticalCVSS 10.0No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution.

    CriticalCVSS 9.9No exploitEPSS 4%

    parallels · remote application serverJul 24, 2020

  • The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a r

    CriticalCVSS 10.0No exploitEPSS 1%

    parallels · remote application serverDec 14, 2023

  • Improper privilege management vulnerability in Parallels Desktop

    CriticalCVSS 10.0No exploitEPSS 0%

    parallels · parallels desktopJun 21, 2024

  • CVE-2013-4878
    39Monitor

    The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAli

    HighCVSS 7.5Proof of conceptEPSS 31%

    parallels · parallels plesk panelJul 18, 2013

  • A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted m

    CriticalCVSS 9.8No exploitEPSS 1%

    Sep 23, 2024

  • CVE-2007-4009
    38Monitor

    PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attack

    CriticalCVSS 9.3Proof of conceptEPSS 4%

    parallels · confixxJul 25, 2007

  • CVE-2011-4851
    38Monitor

    The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete featur

    CriticalCVSS 9.3No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • CVE-2011-4854
    37Monitor

    The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Co

    CriticalCVSS 9.3No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • CVE-2011-4856
    37Monitor

    The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might a

    CriticalCVSS 9.3No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • CVE-2011-4855
    37Monitor

    The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain resources,

    CriticalCVSS 9.3No exploitEPSS 2%

    parallels · parallels plesk panelDec 16, 2011

  • A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879).

    HighCVSS 8.8No exploitEPSS 1%

    parallels · parallels desktopJun 3, 2025

  • CVE-2020-8875
    35Monitor

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123.

    HighCVSS 8.8No exploitEPSS 1%

    parallels · parallels desktopMar 23, 2020