Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Mediavine Control PanelAI | 23/7/2026 | 23/7/2026 | Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | |
| Analizada | Media (5.1) | 0.30% | — | Hestiacp Control Panel | 10/7/2026 | 29/9/2026 | HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply htmlspecialchars() encoding to the DNS record… | |
| Analizada | Alta (8.7) | 3.2% | — | Hestiacp Control Panel | 10/7/2026 | 29/9/2026 | HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient input validation in… | |
| Aplazada | Media (6.5) | 0.44% | — | Control Panel Client Portal PROAI | 17/6/2026 | 17/6/2026 | CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions. | |
| Aplazada | Alta (8.6) | 0.49% | — | Hestia Control PanelAI | 21/1/2026 | 17/6/2026 | Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to write SSH keys or other content to specific file paths on the server. | |
| Aplazada | Alta (8.6) | 2.4% | — | Algo 8028 Control PanelAI | 13/1/2026 | 17/6/2026 | Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code… | |
| Analizada | Crítica (9.8) | 1.1% | — | Magdesign Pocketvj Control Panel Firmware | 5/11/2025 | 17/6/2026 | PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote attackers to execute arbitrary commands… | |
| Analizada | Media (6.5) | 0.34% | — | Magdesign Pocketvj Control Panel Firmware | 23/9/2025 | 17/6/2026 | An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component. | |
| Analizada | Media (6.1) | 0.29% | — | Ehcp Easy Hosting Control Panel | 22/8/2025 | 17/6/2026 | Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template parameter. | |
| Analizada | Media (6.1) | 0.24% | — | Ehcp Easy Hosting Control Panel | 22/8/2025 | 17/6/2026 | Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter. | |
| Modificada | Media (5.4) | 0.23% | — | Ehcp Easy Hosting Control Panel | 21/8/2025 | 17/6/2026 | SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter. | |
| Analizada | Media (6.5) | 0.26% | — | Ehcp Easy Hosting Control Panel | 19/8/2025 | 17/6/2026 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function. | |
| Analizada | Media (4.8) | 0.24% | — | Ehcp Easy Hosting Control Panel | 8/8/2025 | 17/6/2026 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function. | |
| Analizada | Media (6.3) | 0.20% | — | Ehcp Easy Hosting Control Panel | 8/8/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter. | |
| Aplazada | Media (5.3) | 0.49% | — | Mediavine Control PanelAI | 16/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel mediavine-control-panel allows Retrieve Embedded Sensitive Data.This issue affects Mediavine Control Panel: from n/a through <= 2.10.6. | |
| Aplazada | Media (6.5) | 0.26% | — | Mediavine Control PanelAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mediavine Mediavine Control Panel mediavine-control-panel.This issue affects Mediavine Control Panel: from n/a through <= 2.10.4. | |
| Modificada | Alta (7.8) | 0.29% | — | Hestiacp Control Panel | 29/10/2023 | 17/6/2026 | Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9. | |
| Modificada | Alta (8.8) | 0.23% | — | Mediavine Control Panel | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mediavine Mediavine Control Panel plugin <= 2.10.2 versions. | |
| Modificada | Media (6.1) | 1.3% | — | Hestiacp Control Panel | 30/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8. | |
| Modificada | Media (6.1) | 0.38% | — | Mediacp Media Control Panel | 15/2/2023 | 17/6/2026 | Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint. | |
| Modificada | Alta (7.5) | 0.41% | — | Mediacp Media Control Panel | 15/2/2023 | 17/6/2026 | Media CP Media Control Panel latest version. Insufficiently protected credential change. | |
| Modificada | Alta (8.8) | 0.28% | — | Mediacp Media Control Panel | 15/2/2023 | 17/6/2026 | Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint. | |
| Modificada | Alta (7.5) | 0.48% | — | Mediacp Media Control Panel | 15/2/2023 | 17/6/2026 | Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure. | |
| Modificada | Alta (7.8) | 0.23% | — | Vestacp Control Panel | 13/11/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The manipulation leads to argument injection. An attack has to be approached locally. The name of the patch is… | |
| Modificada | Alta (7.2) | 5.6% | — | Vestacp Control PanelVestacp Vesta Control Panel | 24/10/2022 | 17/6/2026 | myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint. |