Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.30%—Hestiacp Control Panel10/7/202629/9/2026
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply htmlspecialchars() encoding to the DNS record…
AnalizadaAlta (8.7)3.2%—Hestiacp Control Panel10/7/202629/9/2026
HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient input validation in…
AplazadaAlta (8.3)0.40%—HestiacpAI4/7/20266/7/2026
HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. This could result in the takeover of administrator users in the application and the underlying webserver.
AplazadaAlta (8.7)0.36%—HestiacpAI19/5/202624/7/2026
HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated from Cloudflare's network. Attackers can…
AplazadaCrítica (9.5)1.5%—HestiacpAI19/5/202614/7/2026
HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remote attackers to achieve root-level code execution. Attackers can inject crafted data into HTTP headers that are…
AplazadaAlta (8.6)0.49%—Hestia Control PanelAI21/1/202617/6/2026
Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to write SSH keys or other content to specific file paths on the server.
AplazadaMedia (5.3)0.27%—Themeisle HestiaAI16/7/202517/6/2026
Missing Authorization vulnerability in themeisle Hestia hestia allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hestia: from n/a through <= 3.2.10.
AplazadaMedia (4.3)0.35%—Juni Hestia Nginx CacheAI2/1/202517/6/2026
Missing Authorization vulnerability in Juni Hestia Nginx Cache hestia-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hestia Nginx Cache: from n/a through <= 2.4.0.
AplazadaMedia (4.3)0.19%—Themeisle HestiaAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in themeisle Hestia hestia allows Cross Site Request Forgery.This issue affects Hestia: from n/a through <= 3.1.2.
ModificadaAlta (7.8)0.29%—Hestiacp Control Panel29/10/202317/6/2026
Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.
ModificadaMedia (5.4)0.40%—Hestiacp13/10/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6.
ModificadaMedia (6.1)0.46%—Hestiacp20/9/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.
ModificadaMedia (6.1)1.3%—Hestiacp Control Panel30/6/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
ModificadaMedia (6.1)0.57%—Hestiacp Control Panel18/8/202217/6/2026
A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
ModificadaAlta (7.5)0.75%—Hestiacp18/8/202217/6/2026
An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being transmitted to the operating system's package manager.
ModificadaAlta (8.8)1.3%—Hestiacp Control Panel5/8/202217/6/2026
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
ModificadaAlta (7.2)1.3%—Hestiacp Control Panel5/8/202217/6/2026
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
ModificadaAlta (8.8)48%—Hestiacp Control Panel27/7/202217/6/2026
OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.
ModificadaAlta (8.8)4.5%—Hestiacp Control Panel28/4/202217/6/2026
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
ModificadaMedia (6.1)0.87%—Hestiacp Control Panel16/3/202217/6/2026
Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.
ModificadaMedia (6.1)0.97%—Hestiacp Control Panel4/3/202217/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.
ModificadaMedia (6.1)1.1%—Hestiacp Control Panel4/3/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.
ModificadaMedia (6.1)0.83%—Hestiacp Control Panel3/3/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.
ModificadaCrítica (9.8)1.1%—Hestiacp Control Panel15/9/202117/6/2026
hestiacp is vulnerable to Use of Wrong Operator in String Comparison
ModificadaMedia (5.4)1.4%—Hestiacp Control Panel16/2/202117/6/2026
Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.