Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)6.0%💥 ExploitMyvestacp MyvestaVestacp Vesta Control Panel15/3/202117/6/2026
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
ModificadaMedia (5.4)1.4%—Hestiacp Control Panel16/2/202117/6/2026
Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.
ModificadaAlta (8.8)2.5%—Vestacp Vesta Control Panel21/4/202017/6/2026
An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).
ModificadaAlta (8.8)4.8%—Vestacp Vesta Control Panel21/4/202017/6/2026
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.
ModificadaMedia (6.5)1.9%—Hestiacp Control PanelVestacp Control Panel25/3/202017/6/2026
In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.
ModificadaAlta (8.8)78%💥 ExploitVestacp Vesta Control Panel22/3/202017/6/2026
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on the server, as demonstrated by an FTP session that renames .bash_logout to a .bash_logout' substring followed by shell metacharacters.
ModificadaAlta (8.8)3.0%—Vestacp Vesta Control Panel10/3/202017/6/2026
Vesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result in remote root access on the server. The platform works with PHP as the frontend language and uses shell scripts to execute system actions. PHP executes shell script through the dangerous command…
ModificadaAlta (8.8)4.9%—Vestacp Control Panel15/8/201917/6/2026
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
ModificadaAlta (8.8)6.5%—Vestacp Control Panel15/8/201917/6/2026
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form.
ModificadaMedia (6.1)1.3%—Vestacp Control Panel19/4/201917/6/2026
Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.
ModificadaCrítica (9.8)1.3%—Vestacp Vesta Control Panel20/12/201817/6/2026
Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information Exposure Through Timing Discrepancy vulnerability in Password reset code -- web/reset/index.php, line 51 that can result in Possible to determine password reset codes, attacker is…
ModificadaMedia (6.1)1.1%—Vestacp Control Panel24/10/201817/6/2026
Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directory/ URI.
ModificadaAlta (7.8)0.35%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt.
ModificadaAlta (7.8)0.46%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.
ModificadaAlta (7.8)0.41%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password.
ModificadaAlta (8.8)10.0%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
ModificadaMedia (6.1)1.0%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.
ModificadaMedia (6.1)38%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.
ModificadaMedia (6.1)1.3%—Vestacp Control Panel6/5/201817/6/2026
An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution via vectors involving a file_put_contents call in web/upload/UploadHandler.php.
ModificadaAlta (8.8)11%💥 ExploitVestacp Control Panel28/2/201817/6/2026
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
ModificadaCrítica (9.8)3.3%—Vivint SKY Control Panel Firmware23/1/201717/6/2026
Vivint Sky Control Panel 1.1.1.9926 allows remote attackers to enable and disable the alarm system and modify other security settings via the Web-enabled interface.
ModificadaMedia (6.8)1.2%—Vestacp Vesta Control Panel18/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack the authentication of arbitrary users.
ModificadaAlta (7.8)3.3%💥 ExploitEntrypass N5200 Active Network Control Panel7/12/201417/6/2026
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or A through D, different vectors than CVE-2014-8868.
ModificadaAlta (7.8)7.0%💥 ExploitEntrypass N5200 Active Network Control Panel7/12/201417/6/2026
EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and password, and possibly other sensitive information, via a request to /4.
ModificadaMedia (6.5)1.1%💥 ExploitInterworx WEB Control Panel21/10/201417/6/2026
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action to the (1) NodeWorx , (2) SiteWorx, or (3) Resellers interface,…
Orbitaley — Vulnerabilidades