Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.29% | — | Ehcp Easy Hosting Control Panel | 22/8/2025 | 17/6/2026 | Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template parameter. | |
| Analizada | Media (6.1) | 0.24% | — | Ehcp Easy Hosting Control Panel | 22/8/2025 | 17/6/2026 | Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter. | |
| Modificada | Media (5.4) | 0.23% | — | Ehcp Easy Hosting Control Panel | 21/8/2025 | 17/6/2026 | SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter. | |
| Analizada | Media (6.5) | 0.26% | — | Ehcp Easy Hosting Control Panel | 19/8/2025 | 17/6/2026 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function. | |
| Analizada | Media (4.8) | 0.24% | — | Ehcp Easy Hosting Control Panel | 8/8/2025 | 17/6/2026 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function. | |
| Analizada | Media (6.3) | 0.20% | — | Ehcp Easy Hosting Control Panel | 8/8/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter. | |
| Modificada | Alta (7.8) | 0.35% | — | Ehcp Easy Hosting Control Panel | 11/5/2018 | 17/6/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt. | |
| Modificada | Alta (7.8) | 0.46% | — | Ehcp Easy Hosting Control Panel | 11/5/2018 | 17/6/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage. | |
| Modificada | Alta (7.8) | 0.41% | — | Ehcp Easy Hosting Control Panel | 11/5/2018 | 17/6/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password. | |
| Modificada | Alta (8.8) | 10.0% | — | Ehcp Easy Hosting Control Panel | 11/5/2018 | 17/6/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection. | |
| Modificada | Media (6.1) | 1.0% | — | Ehcp Easy Hosting Control Panel | 11/5/2018 | 17/6/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie. | |
| Modificada | Media (6.1) | 38% | — | Ehcp Easy Hosting Control Panel | 11/5/2018 | 17/6/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account. | |
| Modificada | Alta (7.5) | 2.4% | — | Easy Hosting Control Panel | 30/11/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the confdir parameter to (1) dbutil.bck.php and (2) dbutil.php in config/. |