Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

451 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9)0.40%—Cpanel WHMAI2/10/20262/10/2026
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
AplazadaCrítica (9)0.40%—Cpanel WHMAI2/10/20262/10/2026
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
Pendiente de análisisCrítica (9.4)0.61%—WP ToolkitAICpanelAI23/9/202624/9/2026
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Pendiente de análisisCrítica (9.4)0.58%—CpanelAI23/9/202624/9/2026
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Pendiente de análisisCrítica (9.9)0.86%—CpanelAICpanel EmailtrackAI9/9/202610/9/2026
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
AnalizadaAlta (8.7)0.88%—Cpanel1/9/202617/9/2026
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
Pendiente de análisisCrítica (9.4)0.56%—CpanelAI31/7/20263/9/2026
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Pendiente de análisisMedia (5.6)0.52%—CpanelAI31/7/20263/9/2026
HTTP Smuggling in cPanel allows potential leak of credentials.
AnalizadaAlta (8.5)0.81%⚠ Explotación activaLitespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin14/6/202623/7/2026
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
Pendiente de análisisCrítica (9.9)0.74%—Cpanel Wordpress ToolkitAI12/6/202617/6/2026
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
AnalizadaAlta (7.5)0.62%—Rurban Cpanel\3/6/202622/7/2026
Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When…
AnalizadaAlta (7.3)0.41%—Rurban Cpanel\3/6/202621/7/2026
Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE (old_value) != SVt_RV && SvTYPE (SvRV…
AnalizadaCrítica (10)1.0%⚠ Explotación activaLitespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin21/5/202623/7/2026
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been…
AnalizadaAlta (8.2)0.32%—CpanelCpanel WP SquaredCpanel WHM13/5/202612/8/2026
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
AnalizadaAlta (8.6)0.38%—CpanelCpanel WP SquaredCpanel WHM13/5/202612/8/2026
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
Pendiente de análisisMedia (5.3)0.52%—Cpanel Nova PluginAI8/5/202617/6/2026
A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home…
AnalizadaCrítica (9.3)99%⚠ Explotación activaCpanelCpanel WHMCpanel WP Squared29/4/202630/9/2026
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
AnalizadaAlta (8.8)0.83%—Cpanel11/12/202517/6/2026
An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.
AplazadaMedia (5.6)0.44%—Cpanel Json XSAI8/9/202517/6/2026
Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
AplazadaMedia (5.5)0.19%—Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAI27/2/202517/6/2026
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux)…
AplazadaAlta (7.1)0.17%—Digitimber Cpanel IntegrationAI3/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DigiTimber DigiTimber cPanel Integration digitimber-cpanel-integration allows Stored XSS.This issue affects DigiTimber cPanel Integration: from n/a through <= 1.4.6.
AplazadaBaja (3.3)0.21%—Acronis Backup Plugin FOR Cpanel AND WHMAI11/11/202417/6/2026
Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892.
AplazadaMedia (5.5)0.20%—Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAIAcronis Backup Plugin FOR DirectadminAI11/11/202417/6/2026
Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build…
AplazadaCrítica (9.9)0.48%—Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAIAcronis Backup Plugin FOR DirectadminAI17/9/202417/6/2026
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.
ModificadaCrítica (9.1)0.79%—Rurban Cpanel\13/2/202417/6/2026
The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.