Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.57%—Hestiacp Control Panel18/8/202217/6/2026
A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
ModificadaAlta (8.8)1.3%—Hestiacp Control Panel5/8/202217/6/2026
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
ModificadaAlta (7.2)1.3%—Hestiacp Control Panel5/8/202217/6/2026
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
ModificadaAlta (8.8)48%—Hestiacp Control Panel27/7/202217/6/2026
OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.
ModificadaMedia (6.1)0.53%—Vestacp Vesta Control Panel19/7/202217/6/2026
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.
ModificadaMedia (6.1)0.53%—Vestacp Vesta Control Panel19/7/202217/6/2026
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.
ModificadaMedia (6.1)0.53%—Vestacp Vesta Control Panel19/7/202217/6/2026
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.
ModificadaMedia (6.1)0.53%—Vestacp Vesta Control Panel19/7/202217/6/2026
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.
ModificadaAlta (8.8)4.5%—Hestiacp Control Panel28/4/202217/6/2026
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
ModificadaMedia (6.1)0.87%—Hestiacp Control Panel16/3/202217/6/2026
Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.
ModificadaMedia (6.1)0.97%—Hestiacp Control Panel4/3/202217/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.
ModificadaMedia (6.1)1.1%—Hestiacp Control Panel4/3/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.
ModificadaMedia (6.1)0.83%—Hestiacp Control Panel3/3/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.
ModificadaCrítica (9.8)1.2%—Vestacp Vesta Control Panel29/11/202117/6/2026
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
ModificadaCrítica (9.8)1.1%—Hestiacp Control Panel15/9/202117/6/2026
hestiacp is vulnerable to Use of Wrong Operator in String Comparison
ModificadaCrítica (9.8)1.7%—Swisslog-healthcare Hmi-3 Control Panel Firmware2/8/202117/6/2026
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root access to the device, which provides permissions for all of the functionality of…
ModificadaAlta (7.5)2.1%—Swisslog-healthcare Hmi-3 Control Panel Firmware2/8/202117/6/2026
A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for…
ModificadaCrítica (9.8)3.4%—Swisslog-healthcare Hmi-3 Control Panel Firmware2/8/202117/6/2026
A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. In the tcpTxThread function, the received data is copied to a stack buffer. An off-by-3 condition can occur, resulting in a stack-based buffer…
ModificadaCrítica (9.8)1.4%—Swisslog-healthcare Hmi-3 Control Panel Firmware2/8/202117/6/2026
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexus Software 7.2.5.7. The device has two user accounts with passwords that are hardcoded.
ModificadaCrítica (9.8)3.3%—Swisslog-healthcare Hmi-3 Control Panel Firmware2/8/202117/6/2026
A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. If an attacker sends a malformed UDP message, a buffer underflow occurs, leading to an out-of-bounds copy and possible remote code execution.
ModificadaCrítica (9.8)3.3%—Swisslog-healthcare Hmi-3 Control Panel Firmware2/8/202117/6/2026
A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, operated by released versions of software before Nexus Software 7.2.5.7. A buffer overflow allows an attacker to overwrite an internal queue data structure and can lead to remote code execution.
ModificadaCrítica (9.8)8.2%—Swisslog-healthcare Hmi-3 Control Panel Firmware2/8/202117/6/2026
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update.
ModificadaCrítica (9.8)3.3%—Swisslog-healthcare Hmi-3 Control Panel Firmware2/8/202117/6/2026
A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code…
ModificadaAlta (7.8)0.50%—Vestacp Control Panel8/4/202117/6/2026
VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a /reset/?action=confirm&user=admin&code= URI. This occurs…
ModificadaAlta (7.2)1.8%—Vestacp Vesta Control Panel8/4/202117/6/2026
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.
Orbitaley — Vulnerabilidades