Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.71% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244). | |
| Modificada | Media (6.3) | 0.95% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243). | |
| Modificada | Media (6.3) | 0.83% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242). | |
| Modificada | Media (4.4) | 0.46% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240). | |
| Modificada | Baja (3.5) | 0.38% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239). | |
| Modificada | Alta (7.3) | 1.3% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238). | |
| Modificada | Alta (7.8) | 0.46% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237). | |
| Modificada | Alta (8.8) | 1.9% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236). | |
| Modificada | Alta (7.8) | 0.43% | — | Cpanel | 2/8/2019 | 17/6/2026 | In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234). | |
| Modificada | Alta (7.5) | 0.88% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941). | |
| Modificada | Media (4.7) | 0.66% | — | Cpanel | 2/8/2019 | 17/6/2026 | In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294). | |
| Modificada | Baja (3.3) | 0.32% | — | Cpanel | 2/8/2019 | 17/6/2026 | In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291). | |
| Modificada | Baja (2.5) | 0.29% | — | Cpanel | 2/8/2019 | 17/6/2026 | In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290). | |
| Modificada | Baja (3.3) | 0.36% | — | Cpanel | 2/8/2019 | 17/6/2026 | In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289). | |
| Modificada | Baja (2.7) | 0.75% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288). | |
| Modificada | Baja (2.5) | 0.28% | — | Cpanel | 2/8/2019 | 17/6/2026 | In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280). | |
| Modificada | Baja (3.3) | 0.36% | — | Cpanel | 2/8/2019 | 17/6/2026 | In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274). | |
| Modificada | Baja (3.3) | 0.36% | — | Cpanel | 2/8/2019 | 17/6/2026 | In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273). | |
| Modificada | Baja (3.3) | 0.36% | — | Cpanel | 2/8/2019 | 17/6/2026 | In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272). | |
| Modificada | Baja (3.3) | 0.32% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265). | |
| Modificada | Media (5.4) | 0.53% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263). | |
| Modificada | Media (5.5) | 0.30% | — | Cpanel | 2/8/2019 | 17/6/2026 | cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303). |