Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.0% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65). | |
| Modificada | Crítica (9.8) | 2.5% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64). | |
| Modificada | Media (6.5) | 1.0% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60). | |
| Modificada | Media (6.5) | 0.96% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29). | |
| Modificada | Crítica (9.8) | 2.6% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91). | |
| Modificada | Media (5.4) | 0.64% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87). | |
| Modificada | Media (5.4) | 0.64% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86). | |
| Modificada | Media (6.5) | 0.96% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85). | |
| Modificada | Media (5.4) | 0.64% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84). | |
| Modificada | Alta (8.8) | 2.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83). | |
| Modificada | Alta (7.5) | 1.3% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221). | |
| Modificada | Media (6.1) | 0.65% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399). | |
| Modificada | Media (6.1) | 0.65% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398). | |
| Modificada | Media (4.3) | 0.63% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396). | |
| Modificada | Baja (2.8) | 0.34% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395). | |
| Modificada | Baja (3.9) | 0.41% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394). | |
| Modificada | Alta (7.2) | 1.0% | — | Cpanel | 1/8/2019 | 17/6/2026 | In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393). | |
| Modificada | Baja (3.3) | 0.34% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443). | |
| Modificada | Baja (2.3) | 0.35% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442). | |
| Modificada | Media (4.3) | 0.63% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439). | |
| Modificada | Media (5.5) | 0.40% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436). | |
| Modificada | Media (4.3) | 0.55% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426). | |
| Modificada | Media (4.4) | 0.35% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425). | |
| Modificada | Media (5.5) | 0.36% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424). | |
| Modificada | Crítica (9.8) | 1.1% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 allows SQL injection during database backups (SEC-420). |