Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

451 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.4%—Cpanel25/9/202017/6/2026
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
ModificadaAlta (7.5)1.4%—Cpanel25/9/202017/6/2026
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
ModificadaAlta (7.5)1.3%—Cpanel25/9/202017/6/2026
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
ModificadaAlta (7.5)1.4%—Cpanel25/9/202017/6/2026
In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).
ModificadaCrítica (9.8)1.4%—Cpanel25/9/202017/6/2026
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
ModificadaCrítica (9.8)1.6%—Cpanel25/9/202017/6/2026
chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
ModificadaAlta (7.5)1.2%—Cpanel25/9/202017/6/2026
cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
ModificadaCrítica (9.8)3.0%—Cpanel25/9/202017/6/2026
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
ModificadaAlta (8.1)0.88%—Cpanel11/5/202017/6/2026
cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540).
ModificadaMedia (5.3)1.3%—Cpanel11/5/202017/6/2026
cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505).
ModificadaMedia (6.5)0.87%—Cpanel17/3/202017/6/2026
cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).
ModificadaCrítica (9.8)1.8%—Cpanel17/3/202017/6/2026
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
ModificadaAlta (7.2)2.7%—Cpanel17/3/202017/6/2026
cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
ModificadaCrítica (9.8)2.2%—Cpanel17/3/202017/6/2026
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
ModificadaCrítica (9.1)1.0%—Cpanel17/3/202017/6/2026
cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).
ModificadaCrítica (9.1)1.0%—Cpanel17/3/202017/6/2026
cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).
ModificadaMedia (5.3)0.84%—Cpanel17/3/202017/6/2026
cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541).
ModificadaAlta (7.2)1.8%—Cpanel17/3/202017/6/2026
cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
ModificadaMedia (6.1)0.64%—Cpanel17/3/202017/6/2026
cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
ModificadaMedia (6.1)0.64%—Cpanel17/3/202017/6/2026
cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).
ModificadaCrítica (9.8)1.6%—Cpanel17/3/202017/6/2026
cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
ModificadaMedia (5.4)0.60%—Cpanel17/3/202017/6/2026
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
ModificadaMedia (5.5)0.29%—Cpanel17/3/202017/6/2026
cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
ModificadaMedia (6.5)0.99%—Cpanel17/3/202017/6/2026
cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).
ModificadaBaja (3.3)0.30%—Cpanel17/3/202017/6/2026
In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).