Parallels maintains a portfolio spanning virtualization platforms, server management systems, and hosting control panels that serve both individual users and service providers. The vendor's vulnerability profile clusters around a modest but durable set of products—notably Parallels Desktop and its Plesk server-management suite—with recurring exposure in information-disclosure weaknesses, input-validation flaws including cross-site scripting, and memory-safety issues such as out-of-bounds reads. These weakness classes reflect the complexity inherent in virtualization layers, web-facing control panels, and privileged management interfaces that mediate access to hosted environments. Defenders should monitor this vendor's advisories in the context of their deployment footprint; virtualization and hosting-infrastructure updates warrant expedited review given the breadth of systems a single host can affect. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Parallels over time
Signals from CVEs in this vendor scope (155 CVEs).
155 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4878HIGH The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it | Jul 18, 2013 | 7.5 | 44 | NO | YES |
CVE-2007-4009HIGH PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackers to execute arbitrary PHP code via a | Jul 26, 2007 | 9.3 | 34 | NO | YES |
CVE-2011-4757HIGH Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authent | Dec 16, 2011 | 10.0 | 29 | NO | NO |
CVE-2021-34869HIGH This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute l | Jan 25, 2022 | 8.8 | 28 | NO | NO |
CVE-2011-4755HIGH Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial | Dec 16, 2011 | 10.0 | 28 | NO | NO |
CVE-2011-4730HIGH The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the autocomplete feature, which makes it easier | Dec 16, 2011 | 10.0 | 28 | NO | NO |
CVE-2011-4727HIGH The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended for storage in an XML document, which all | Dec 16, 2011 | 10.0 | 28 | NO | NO |
CVE-2008-6479MEDIUM Cross-site request forgery (CSRF) vulnerability in the "change password" feature in the VZPP web interface for Parallels Virtuozzo 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remo | Mar 16, 2009 | 6.8 | 28 | NO | YES |
CVE-2024-6240CRITICAL Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate | Jun 21, 2024 | 10.0 | 27 | NO | NO |
CVE-2023-45894CRITICAL The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code ex | Dec 14, 2023 | 10.0 | 27 | NO | NO |
Signals from CVEs in this vendor scope (155 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Parallels.
Media articles that mention a CVE ID that affects a product developed by Parallels — matched by CVE ID, not by vendor name.