Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

451 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.31%—Cpanel7/8/201917/6/2026
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).
ModificadaMedia (6.8)0.53%—Cpanel7/8/201917/6/2026
cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134).
ModificadaMedia (4.3)0.44%—Cpanel6/8/201917/6/2026
cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133).
ModificadaBaja (3.3)0.39%—Cpanel6/8/201917/6/2026
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).
ModificadaMedia (6.1)0.65%—Cpanel6/8/201917/6/2026
cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156).
ModificadaMedia (6.5)0.88%—Cpanel6/8/201917/6/2026
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
ModificadaAlta (8.8)1.5%—Cpanel6/8/201917/6/2026
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).
ModificadaAlta (8.8)1.2%—Cpanel6/8/201917/6/2026
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
ModificadaMedia (5.3)0.77%—Cpanel6/8/201917/6/2026
cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-9559).
ModificadaAlta (7.5)1.1%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192).
ModificadaAlta (8.8)1.5%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
ModificadaAlta (8.8)1.9%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
ModificadaAlta (8.1)0.89%—Cpanel6/8/201917/6/2026
The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).
ModificadaMedia (6.5)0.88%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
ModificadaMedia (6.5)0.88%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
ModificadaMedia (5.4)0.53%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
ModificadaMedia (5.4)0.53%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).
ModificadaMedia (5.4)0.53%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).
ModificadaMedia (5.4)0.53%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).
ModificadaMedia (5.4)0.53%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).
ModificadaMedia (5.4)0.53%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179).
ModificadaMedia (5.4)0.53%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).
ModificadaMedia (5.4)0.54%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).
ModificadaMedia (5.4)0.53%—Cpanel6/8/201917/6/2026
cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).
ModificadaMedia (6.5)0.91%—Cpanel5/8/201917/6/2026
cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).