Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.4% | — | Cpanel | 25/9/2020 | 17/6/2026 | In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554). | |
| Modificada | Alta (7.5) | 1.4% | — | Cpanel | 25/9/2020 | 17/6/2026 | In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552). | |
| Modificada | Alta (7.5) | 1.3% | — | Cpanel | 25/9/2020 | 17/6/2026 | In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551). | |
| Modificada | Alta (7.5) | 1.4% | — | Cpanel | 25/9/2020 | 17/6/2026 | In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550). | |
| Modificada | Crítica (9.8) | 1.4% | — | Cpanel | 25/9/2020 | 17/6/2026 | In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549). | |
| Modificada | Crítica (9.8) | 1.6% | — | Cpanel | 25/9/2020 | 17/6/2026 | chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497). | |
| Modificada | Alta (7.5) | 1.2% | — | Cpanel | 25/9/2020 | 17/6/2026 | cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491). | |
| Modificada | Crítica (9.8) | 3.0% | — | Cpanel | 25/9/2020 | 17/6/2026 | cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485). | |
| Modificada | Alta (8.1) | 0.88% | — | Cpanel | 11/5/2020 | 17/6/2026 | cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540). | |
| Modificada | Media (5.3) | 1.3% | — | Cpanel | 11/5/2020 | 17/6/2026 | cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505). | |
| Modificada | Media (6.5) | 0.87% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547). | |
| Modificada | Crítica (9.8) | 1.8% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546). | |
| Modificada | Alta (7.2) | 2.7% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545). | |
| Modificada | Crítica (9.8) | 2.2% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544). | |
| Modificada | Crítica (9.1) | 1.0% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543). | |
| Modificada | Crítica (9.1) | 1.0% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542). | |
| Modificada | Media (5.3) | 0.84% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541). | |
| Modificada | Alta (7.2) | 1.8% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537). | |
| Modificada | Media (6.1) | 0.64% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535). | |
| Modificada | Media (6.1) | 0.64% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515). | |
| Modificada | Crítica (9.8) | 1.6% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534). | |
| Modificada | Media (5.4) | 0.60% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533). | |
| Modificada | Media (5.5) | 0.29% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532). | |
| Modificada | Media (6.5) | 0.99% | — | Cpanel | 17/3/2020 | 17/6/2026 | cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531). | |
| Modificada | Baja (3.3) | 0.30% | — | Cpanel | 17/3/2020 | 17/6/2026 | In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525). |