Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

451 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.74%—Cpanel17/3/202017/6/2026
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
ModificadaAlta (8.8)1.3%—Cpanel17/3/202017/6/2026
cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).
ModificadaAlta (8.8)1.1%—Cpanel17/3/202017/6/2026
cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
ModificadaMedia (5.4)0.71%—Cpanel16/3/202017/6/2026
cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).
ModificadaMedia (5.4)0.59%—CpanelCpanel WHM10/2/202016/6/2026
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
ModificadaMedia (6.1)1.5%💥 ExploitCpanel Webhost Manager27/1/202016/6/2026
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.1)0.78%—Cpanel9/10/201917/6/2026
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
ModificadaMedia (6.1)0.78%—Cpanel9/10/201917/6/2026
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
ModificadaMedia (6.1)0.78%—Cpanel9/10/201917/6/2026
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
ModificadaMedia (6.1)0.78%—Cpanel9/10/201917/6/2026
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
ModificadaMedia (6.1)0.48%—Cpanel9/10/201917/6/2026
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
ModificadaAlta (8.8)1.1%—Cpanel9/10/201917/6/2026
cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).
ModificadaAlta (8.8)1.3%—Cpanel7/8/201917/6/2026
In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).
ModificadaAlta (8.8)1.3%—Cpanel7/8/201917/6/2026
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
ModificadaAlta (8.8)1.3%—Cpanel7/8/201917/6/2026
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
ModificadaAlta (8.8)1.3%—Cpanel7/8/201917/6/2026
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
ModificadaAlta (8.8)1.3%—Cpanel7/8/201917/6/2026
In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).
ModificadaMedia (6.5)0.91%—Cpanel7/8/201917/6/2026
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).
ModificadaMedia (5.4)0.53%—Cpanel7/8/201917/6/2026
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).
ModificadaAlta (8.8)1.5%—Cpanel7/8/201917/6/2026
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).
ModificadaAlta (8.1)1.1%—Cpanel7/8/201917/6/2026
The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58).
ModificadaAlta (7.5)0.88%—Cpanel7/8/201917/6/2026
cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).
ModificadaAlta (8.8)1.2%—Cpanel7/8/201917/6/2026
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).
ModificadaAlta (8.8)1.1%—Cpanel7/8/201917/6/2026
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).
ModificadaAlta (7.8)0.95%—Cpanel7/8/201917/6/2026
cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138).