Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

451 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.0%—Cpanel1/8/201917/6/2026
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
ModificadaCrítica (9.8)2.5%—Cpanel1/8/201917/6/2026
cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
ModificadaMedia (6.5)1.0%—Cpanel1/8/201917/6/2026
cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).
ModificadaMedia (6.5)0.96%—Cpanel1/8/201917/6/2026
cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
ModificadaCrítica (9.8)2.6%—Cpanel1/8/201917/6/2026
cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
ModificadaMedia (5.4)0.64%—Cpanel1/8/201917/6/2026
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
ModificadaMedia (5.4)0.64%—Cpanel1/8/201917/6/2026
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).
ModificadaMedia (6.5)0.96%—Cpanel1/8/201917/6/2026
cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).
ModificadaMedia (5.4)0.64%—Cpanel1/8/201917/6/2026
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
ModificadaAlta (8.8)2.1%—Cpanel1/8/201917/6/2026
cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
ModificadaAlta (7.5)1.3%—Cpanel1/8/201917/6/2026
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
ModificadaMedia (6.1)0.65%—Cpanel1/8/201917/6/2026
cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).
ModificadaMedia (6.1)0.65%—Cpanel1/8/201917/6/2026
cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).
ModificadaMedia (4.3)0.63%—Cpanel1/8/201917/6/2026
cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).
ModificadaBaja (2.8)0.34%—Cpanel1/8/201917/6/2026
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
ModificadaBaja (3.9)0.41%—Cpanel1/8/201917/6/2026
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
ModificadaAlta (7.2)1.0%—Cpanel1/8/201917/6/2026
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
ModificadaBaja (3.3)0.34%—Cpanel1/8/201917/6/2026
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
ModificadaBaja (2.3)0.35%—Cpanel1/8/201917/6/2026
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
ModificadaMedia (4.3)0.63%—Cpanel1/8/201917/6/2026
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).
ModificadaMedia (5.5)0.40%—Cpanel1/8/201917/6/2026
cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
ModificadaMedia (4.3)0.55%—Cpanel1/8/201917/6/2026
cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).
ModificadaMedia (4.4)0.35%—Cpanel1/8/201917/6/2026
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
ModificadaMedia (5.5)0.36%—Cpanel1/8/201917/6/2026
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
ModificadaCrítica (9.8)1.1%—Cpanel1/8/201917/6/2026
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
Orbitaley — Vulnerabilidades