Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2022-3967 A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the … Control Panel 2022-07-18+ Fix from $1,9502022-11-13 HIGH 7.2 CVE-2021-46850EPSS 5% myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote adm… Control Panel 0.9.8-26 / 0.9.8-26-43+ Fix from $1,9502022-10-24 MEDIUM 6.1 CVE-2022-36304 Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHa… Vesta Control Panel No fix yet Fix from $1,6002022-07-19 MEDIUM 6.1 CVE-2022-36305 Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php. Vesta Control Panel No fix yet Fix from $1,6002022-07-19 MEDIUM 6.1 CVE-2022-34025 Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php. Vesta Control Panel No fix yet Fix from $1,6002022-07-19 MEDIUM 6.1 CVE-2022-36303 Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadH… Vesta Control Panel No fix yet Fix from $1,6002022-07-19 CRITICAL 9.8 CVE-2021-43693 vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php. Vesta Control Panel No fix yet Fix from $2,3002021-11-29 HIGH 7.8 CVE-2021-30463 VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY va… Control Panel after 0.9.8-24 Fix from $1,9502021-04-08 HIGH 7.2 CVE-2021-30462 VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/… Vesta Control Panel after 0.9.8-24 Fix from $1,9502021-04-08 HIGH 8.8 CVE-2020-10786 A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron… Vesta Control Panel after 0.9.8-26 Fix from $1,9502020-04-21 HIGH 8.8 CVE-2020-10787 An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-u… Vesta Control Panel after 0.9.8-26 Fix from $1,9502020-04-21 HIGH 8.8 CVE-2020-10808EPSS 78% Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to… Vesta Control Panel after 0.9.8-26 Fix from $1,9502020-03-22 HIGH 8.8 CVE-2019-9859 Vesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result in remote root access on the… Vesta Control Panel after 0.9.8-23 Fix from $1,9502020-03-10 HIGH 8.8 CVE-2019-12791EPSS 6% A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular regist… Control Panel No fix yet Fix from $1,9502019-08-15 HIGH 8.8 CVE-2019-12792 A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered us… Control Panel No fix yet Fix from $1,9502019-08-15 MEDIUM 6.1 CVE-2019-9841 Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL. Control Panel Patch available Fix from $1,6002019-04-19 CRITICAL 9.8 CVE-2018-1000884 Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information Exposure … Vesta Control Panel 0.9.8-18+ Fix from $2,3002018-12-20 MEDIUM 6.1 CVE-2018-18547 Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, t… Control Panel after 0.9.8-22 Fix from $1,6002018-10-24 MEDIUM 6.1 CVE-2018-10686 An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead … Control Panel No fix yet Fix from $1,6002018-05-06 HIGH 8.8 CVE-2015-4117EPSS 11% Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter … Control Panel 0.9.8-14+ Fix from $1,9502018-02-28 MEDIUM 6.8 CVE-2015-2861 Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack the authentication of arbitr… Vesta Control Panel after 0.9.8-12 Fix from $1,6002015-06-18