Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.35% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356). | |
| Modificada | Baja (3.3) | 0.35% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355). | |
| Modificada | Media (5.7) | 0.63% | — | Cpanel | 1/8/2019 | 17/6/2026 | bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354). | |
| Modificada | Baja (3.3) | 0.35% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353). | |
| Modificada | Baja (2.5) | 0.29% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352). | |
| Modificada | Baja (2.5) | 0.29% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351). | |
| Modificada | Media (5.6) | 0.31% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349). | |
| Modificada | Baja (3.3) | 0.27% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342). | |
| Modificada | Baja (3.3) | 0.35% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339). | |
| Modificada | Baja (2.7) | 0.59% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324). | |
| Modificada | Media (4.3) | 0.55% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321). | |
| Modificada | Baja (3.3) | 0.32% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308). | |
| Modificada | Media (4.3) | 0.88% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107). | |
| Modificada | Alta (8.8) | 1.4% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105). | |
| Modificada | Alta (7.5) | 1.3% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104). | |
| Modificada | Media (6.5) | 0.98% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102). | |
| Modificada | Alta (7.2) | 1.4% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101). | |
| Modificada | Alta (8.1) | 0.98% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100). | |
| Modificada | Media (6.5) | 1.0% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99). | |
| Modificada | Alta (8.8) | 2.6% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97). | |
| Modificada | Media (5.4) | 0.64% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96). | |
| Modificada | Alta (8.1) | 1.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92). | |
| Modificada | Crítica (9.8) | 2.5% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90). | |
| Modificada | Alta (8.8) | 2.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89). | |
| Modificada | Media (5.4) | 0.64% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88). |