Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.57% | — | Hestiacp Control Panel | 18/8/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Alta (8.8) | 1.3% | — | Hestiacp Control Panel | 5/8/2022 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. | |
| Modificada | Alta (7.2) | 1.3% | — | Hestiacp Control Panel | 5/8/2022 | 17/6/2026 | Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. | |
| Modificada | Alta (8.8) | 48% | — | Hestiacp Control Panel | 27/7/2022 | 17/6/2026 | OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5. | |
| Modificada | Media (6.1) | 0.53% | — | Vestacp Vesta Control Panel | 19/7/2022 | 17/6/2026 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php. | |
| Modificada | Media (6.1) | 0.53% | — | Vestacp Vesta Control Panel | 19/7/2022 | 17/6/2026 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php. | |
| Modificada | Media (6.1) | 0.53% | — | Vestacp Vesta Control Panel | 19/7/2022 | 17/6/2026 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php. | |
| Modificada | Media (6.1) | 0.53% | — | Vestacp Vesta Control Panel | 19/7/2022 | 17/6/2026 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php. | |
| Modificada | Alta (8.8) | 4.5% | — | Hestiacp Control Panel | 28/4/2022 | 17/6/2026 | Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context. | |
| Modificada | Media (6.1) | 0.87% | — | Hestiacp Control Panel | 16/3/2022 | 17/6/2026 | Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11. | |
| Modificada | Media (6.1) | 0.97% | — | Hestiacp Control Panel | 4/3/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9. | |
| Modificada | Media (6.1) | 1.1% | — | Hestiacp Control Panel | 4/3/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10. | |
| Modificada | Media (6.1) | 0.83% | — | Hestiacp Control Panel | 3/3/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9. | |
| Modificada | Crítica (9.8) | 1.2% | — | Vestacp Vesta Control Panel | 29/11/2021 | 17/6/2026 | vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Hestiacp Control Panel | 15/9/2021 | 17/6/2026 | hestiacp is vulnerable to Use of Wrong Operator in String Comparison | |
| Modificada | Crítica (9.8) | 1.7% | — | Swisslog-healthcare Hmi-3 Control Panel Firmware | 2/8/2021 | 17/6/2026 | An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root access to the device, which provides permissions for all of the functionality of… | |
| Modificada | Alta (7.5) | 2.1% | — | Swisslog-healthcare Hmi-3 Control Panel Firmware | 2/8/2021 | 17/6/2026 | A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for… | |
| Modificada | Crítica (9.8) | 3.4% | — | Swisslog-healthcare Hmi-3 Control Panel Firmware | 2/8/2021 | 17/6/2026 | A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. In the tcpTxThread function, the received data is copied to a stack buffer. An off-by-3 condition can occur, resulting in a stack-based buffer… | |
| Modificada | Crítica (9.8) | 1.4% | — | Swisslog-healthcare Hmi-3 Control Panel Firmware | 2/8/2021 | 17/6/2026 | An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexus Software 7.2.5.7. The device has two user accounts with passwords that are hardcoded. | |
| Modificada | Crítica (9.8) | 3.3% | — | Swisslog-healthcare Hmi-3 Control Panel Firmware | 2/8/2021 | 17/6/2026 | A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. If an attacker sends a malformed UDP message, a buffer underflow occurs, leading to an out-of-bounds copy and possible remote code execution. | |
| Modificada | Crítica (9.8) | 3.3% | — | Swisslog-healthcare Hmi-3 Control Panel Firmware | 2/8/2021 | 17/6/2026 | A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, operated by released versions of software before Nexus Software 7.2.5.7. A buffer overflow allows an attacker to overwrite an internal queue data structure and can lead to remote code execution. | |
| Modificada | Crítica (9.8) | 8.2% | — | Swisslog-healthcare Hmi-3 Control Panel Firmware | 2/8/2021 | 17/6/2026 | A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update. | |
| Modificada | Crítica (9.8) | 3.3% | — | Swisslog-healthcare Hmi-3 Control Panel Firmware | 2/8/2021 | 17/6/2026 | A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code… | |
| Modificada | Alta (7.8) | 0.50% | — | Vestacp Control Panel | 8/4/2021 | 17/6/2026 | VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a /reset/?action=confirm&user=admin&code= URI. This occurs… | |
| Modificada | Alta (7.2) | 1.8% | — | Vestacp Vesta Control Panel | 8/4/2021 | 17/6/2026 | VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts. |