Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412). | |
| Modificada | Media (6.5) | 0.88% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410). | |
| Modificada | Baja (2.7) | 0.70% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406). | |
| Modificada | Media (6.3) | 0.98% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405). | |
| Modificada | Media (6.5) | 0.72% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401). | |
| Modificada | Media (6.1) | 0.65% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392). | |
| Modificada | Media (6.1) | 0.65% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391). | |
| Modificada | Baja (3.8) | 0.32% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382). | |
| Modificada | Media (6.7) | 0.39% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380). | |
| Modificada | Media (6.7) | 0.31% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379). | |
| Modificada | Media (5.5) | 0.83% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378). | |
| Modificada | Media (6.5) | 0.94% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82). | |
| Modificada | Alta (7.2) | 1.4% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81). | |
| Modificada | Alta (8.1) | 1.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80). | |
| Modificada | Alta (8.1) | 1.3% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79). | |
| Modificada | Alta (8.1) | 1.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78). | |
| Modificada | Media (6.5) | 1.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77). | |
| Modificada | Alta (8.1) | 1.4% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76). | |
| Modificada | Media (6.5) | 1.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74). | |
| Modificada | Media (5.3) | 0.87% | — | Cpanel | 1/8/2019 | 17/6/2026 | The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73). | |
| Modificada | Alta (8.8) | 2.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72). | |
| Modificada | Alta (8.1) | 1.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71). | |
| Modificada | Media (6.5) | 1.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70). | |
| Modificada | Alta (7.5) | 1.5% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46). |