Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.29%—Ehcp Easy Hosting Control Panel22/8/202517/6/2026
Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template parameter.
AnalizadaMedia (6.1)0.24%—Ehcp Easy Hosting Control Panel22/8/202517/6/2026
Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter.
ModificadaMedia (5.4)0.23%—Ehcp Easy Hosting Control Panel21/8/202517/6/2026
SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter.
AnalizadaMedia (6.5)0.26%—Ehcp Easy Hosting Control Panel19/8/202517/6/2026
Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function.
AnalizadaMedia (4.8)0.24%—Ehcp Easy Hosting Control Panel8/8/202517/6/2026
Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function.
AnalizadaMedia (6.3)0.20%—Ehcp Easy Hosting Control Panel8/8/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter.
ModificadaAlta (7.8)0.35%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt.
ModificadaAlta (7.8)0.46%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.
ModificadaAlta (7.8)0.41%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password.
ModificadaAlta (8.8)10.0%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
ModificadaMedia (6.1)1.0%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.
ModificadaMedia (6.1)38%—Ehcp Easy Hosting Control Panel11/5/201817/6/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.
ModificadaAlta (7.5)2.4%—Easy Hosting Control Panel30/11/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the confdir parameter to (1) dbutil.bck.php and (2) dbutil.php in config/.