Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.35% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418). | |
| Modificada | Media (5.3) | 0.84% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416). | |
| Modificada | Media (5.4) | 0.52% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367). | |
| Modificada | Media (6.5) | 0.73% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 allows FTP access during account suspension (SEC-449). | |
| Modificada | Media (6.8) | 0.38% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447). | |
| Modificada | Media (5.4) | 0.52% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446). | |
| Modificada | Baja (3.3) | 0.34% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445). | |
| Modificada | Media (6.3) | 0.99% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444). | |
| Modificada | Media (5.4) | 0.52% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441). | |
| Modificada | Media (5.4) | 0.52% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437). | |
| Modificada | Media (5.4) | 0.52% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434). | |
| Modificada | Media (5.4) | 0.52% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428). | |
| Modificada | Baja (3.3) | 0.33% | — | Cpanel | 1/8/2019 | 17/6/2026 | cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409). | |
| Modificada | Baja (3.3) | 0.34% | — | Cpanel | 30/7/2019 | 17/6/2026 | In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478). | |
| Modificada | Media (4.3) | 0.63% | — | Cpanel | 30/7/2019 | 17/6/2026 | cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476). | |
| Modificada | Baja (3.3) | 0.41% | — | Cpanel | 30/7/2019 | 17/6/2026 | Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474). | |
| Modificada | Media (5.3) | 0.77% | — | Cpanel | 30/7/2019 | 17/6/2026 | cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473). | |
| Modificada | Baja (3.3) | 0.41% | — | Cpanel | 30/7/2019 | 17/6/2026 | Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472). | |
| Modificada | Media (5.5) | 0.38% | — | Cpanel | 30/7/2019 | 17/6/2026 | cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466). | |
| Modificada | Media (4.3) | 0.63% | — | Cpanel | 30/7/2019 | 17/6/2026 | cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460). | |
| Modificada | Baja (2.7) | 0.75% | — | Cpanel | 30/7/2019 | 17/6/2026 | cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415). | |
| Modificada | Media (6.1) | 0.65% | — | Cpanel | 30/7/2019 | 17/6/2026 | cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493). | |
| Modificada | Alta (8.8) | 1.5% | — | Cpanel | 30/7/2019 | 17/6/2026 | cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487). | |
| Modificada | Media (5.5) | 0.40% | — | Cpanel | 30/7/2019 | 17/6/2026 | cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484). |