Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.31% | — | Cpanel | 7/8/2019 | 17/6/2026 | cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137). | |
| Modificada | Media (6.8) | 0.53% | — | Cpanel | 7/8/2019 | 17/6/2026 | cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134). | |
| Modificada | Media (4.3) | 0.44% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133). | |
| Modificada | Baja (3.3) | 0.39% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130). | |
| Modificada | Media (6.1) | 0.65% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156). | |
| Modificada | Media (6.5) | 0.88% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154). | |
| Modificada | Alta (8.8) | 1.5% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152). | |
| Modificada | Alta (8.8) | 1.2% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141). | |
| Modificada | Media (5.3) | 0.77% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-9559). | |
| Modificada | Alta (7.5) | 1.1% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192). | |
| Modificada | Alta (8.8) | 1.5% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191). | |
| Modificada | Alta (8.8) | 1.9% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188). | |
| Modificada | Alta (8.1) | 0.89% | — | Cpanel | 6/8/2019 | 17/6/2026 | The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187). | |
| Modificada | Media (6.5) | 0.88% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186). | |
| Modificada | Media (6.5) | 0.88% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178). | |
| Modificada | Media (5.4) | 0.54% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 6/8/2019 | 17/6/2026 | cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174). | |
| Modificada | Media (6.5) | 0.91% | — | Cpanel | 5/8/2019 | 17/6/2026 | cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213). |