Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.25%—Mediavine Control PanelAI23/7/202623/7/2026
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
AnalizadaMedia (5.1)0.30%—Hestiacp Control Panel10/7/202629/9/2026
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply htmlspecialchars() encoding to the DNS record…
AnalizadaAlta (8.7)3.2%—Hestiacp Control Panel10/7/202629/9/2026
HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient input validation in…
AplazadaMedia (6.5)0.44%—Control Panel Client Portal PROAI17/6/202617/6/2026
CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.
AplazadaAlta (8.6)0.49%—Hestia Control PanelAI21/1/202617/6/2026
Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to write SSH keys or other content to specific file paths on the server.
AplazadaAlta (8.6)2.4%—Algo 8028 Control PanelAI13/1/202617/6/2026
Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code…
AnalizadaCrítica (9.8)1.1%—Magdesign Pocketvj Control Panel Firmware5/11/202517/6/2026
PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote attackers to execute arbitrary commands…
AnalizadaMedia (6.5)0.34%—Magdesign Pocketvj Control Panel Firmware23/9/202517/6/2026
An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.
AnalizadaMedia (6.1)0.29%—Ehcp Easy Hosting Control Panel22/8/202517/6/2026
Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template parameter.
AnalizadaMedia (6.1)0.24%—Ehcp Easy Hosting Control Panel22/8/202517/6/2026
Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter.
ModificadaMedia (5.4)0.23%—Ehcp Easy Hosting Control Panel21/8/202517/6/2026
SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter.
AnalizadaMedia (6.5)0.26%—Ehcp Easy Hosting Control Panel19/8/202517/6/2026
Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function.
AnalizadaMedia (4.8)0.24%—Ehcp Easy Hosting Control Panel8/8/202517/6/2026
Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function.
AnalizadaMedia (6.3)0.20%—Ehcp Easy Hosting Control Panel8/8/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter.
AplazadaMedia (5.3)0.49%—Mediavine Control PanelAI16/4/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel mediavine-control-panel allows Retrieve Embedded Sensitive Data.This issue affects Mediavine Control Panel: from n/a through <= 2.10.6.
AplazadaMedia (6.5)0.26%—Mediavine Control PanelAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mediavine Mediavine Control Panel mediavine-control-panel.This issue affects Mediavine Control Panel: from n/a through <= 2.10.4.
ModificadaAlta (7.8)0.29%—Hestiacp Control Panel29/10/202317/6/2026
Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.
ModificadaAlta (8.8)0.23%—Mediavine Control Panel10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mediavine Mediavine Control Panel plugin <= 2.10.2 versions.
ModificadaMedia (6.1)1.3%—Hestiacp Control Panel30/6/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
ModificadaMedia (6.1)0.38%—Mediacp Media Control Panel15/2/202317/6/2026
Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.
ModificadaAlta (7.5)0.41%—Mediacp Media Control Panel15/2/202317/6/2026
Media CP Media Control Panel latest version. Insufficiently protected credential change.
ModificadaAlta (8.8)0.28%—Mediacp Media Control Panel15/2/202317/6/2026
Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.
ModificadaAlta (7.5)0.48%—Mediacp Media Control Panel15/2/202317/6/2026
Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.
ModificadaAlta (7.8)0.23%—Vestacp Control Panel13/11/202217/6/2026
A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The manipulation leads to argument injection. An attack has to be approached locally. The name of the patch is…
ModificadaAlta (7.2)5.6%—Vestacp Control PanelVestacp Vesta Control Panel24/10/202217/6/2026
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.