hestiacp CVE 脆弱性と CVE 一覧(17)

製品(CPE): — CVE 件数: 17

hestiacp 脆弱性概要

hestiacp 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

一般的な弱点パターンには vendor risk cross-site scripting and vendor risk command injection があり、vendor surface software deployment and vendor surface production workloads の利用場面で vendor impact session compromise などのリスクが生じる可能性があります。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 117 / 17 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2023-5839 Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9. [email protected] 7.8 0.05% 2023-10-29 2024-11-21
CVE-2023-4517 Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6. [email protected] 5.4 0.07% 2023-10-13 2024-11-21
CVE-2023-5084 Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8. [email protected] 3.9 0.08% 2023-09-20 2024-11-21
CVE-2023-3479 Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8. [email protected] 6.1 23.52% 2023-06-30 2024-11-21
CVE-2021-30071 A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. [email protected] 6.1 0.23% 2022-08-18 2024-11-21
CVE-2021-30070 An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being transmitted to the operating system's package manager. [email protected] 7.5 0.23% 2022-08-18 2024-11-21
CVE-2022-2636 Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. [email protected] 8.5 0.42% 2022-08-05 2026-02-25
CVE-2022-2626 Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. [email protected] 7.2 0.35% 2022-08-05 2024-11-21
CVE-2022-2550 OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5. [email protected] 8.8 8.79% 2022-07-27 2024-11-21
CVE-2022-1509 Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context. [email protected] 9.9 1.68% 2022-04-28 2024-11-21
CVE-2022-0986 Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11. [email protected] 6.1 0.32% 2022-03-16 2024-11-21
CVE-2022-0752 Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9. [email protected] 6.1 0.30% 2022-03-04 2024-11-21
CVE-2022-0838 Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10. [email protected] 6.1 0.87% 2022-03-04 2024-11-21
CVE-2022-0753 Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9. [email protected] 6.1 0.28% 2022-03-03 2024-11-21
CVE-2021-3797 hestiacp is vulnerable to Use of Wrong Operator in String Comparison [email protected] 9.8 0.44% 2021-09-15 2024-11-21
CVE-2021-27231 Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages. [email protected] 5.4 0.32% 2021-02-16 2024-11-21
CVE-2020-10966 In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name. [email protected] 6.5 0.51% 2020-03-25 2024-11-21
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence