Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9) | 0.40% | — | Cpanel WHMAI | 2/10/2026 | 2/10/2026 | There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface. | |
| Aplazada | Crítica (9) | 0.40% | — | Cpanel WHMAI | 2/10/2026 | 2/10/2026 | There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface. | |
| Pendiente de análisis | Crítica (9.4) | 0.61% | — | WP ToolkitAICpanelAI | 23/9/2026 | 24/9/2026 | Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts. | |
| Pendiente de análisis | Crítica (9.4) | 0.58% | — | CpanelAI | 23/9/2026 | 24/9/2026 | Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges. | |
| Pendiente de análisis | Crítica (9.9) | 0.86% | — | CpanelAICpanel EmailtrackAI | 9/9/2026 | 10/9/2026 | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component | |
| Analizada | Alta (8.7) | 0.88% | — | Cpanel | 1/9/2026 | 17/9/2026 | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. | |
| Pendiente de análisis | Crítica (9.4) | 0.56% | — | CpanelAI | 31/7/2026 | 3/9/2026 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | |
| Pendiente de análisis | Media (5.6) | 0.52% | — | CpanelAI | 31/7/2026 | 3/9/2026 | HTTP Smuggling in cPanel allows potential leak of credentials. | |
| Analizada | Alta (8.5) | 0.81% | ⚠ Explotación activa | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 14/6/2026 | 23/7/2026 | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026. | |
| Pendiente de análisis | Crítica (9.9) | 0.74% | — | Cpanel Wordpress ToolkitAI | 12/6/2026 | 17/6/2026 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account. | |
| Analizada | Alta (7.5) | 0.62% | — | Rurban Cpanel\ | 3/6/2026 | 22/7/2026 | Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When… | |
| Analizada | Alta (7.3) | 0.41% | — | Rurban Cpanel\ | 3/6/2026 | 21/7/2026 | Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE (old_value) != SVt_RV && SvTYPE (SvRV… | |
| Analizada | Crítica (10) | 1.0% | ⚠ Explotación activa | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 21/5/2026 | 23/7/2026 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been… | |
| Analizada | Alta (8.2) | 0.32% | — | CpanelCpanel WP SquaredCpanel WHM | 13/5/2026 | 12/8/2026 | SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. | |
| Analizada | Alta (8.6) | 0.38% | — | CpanelCpanel WP SquaredCpanel WHM | 13/5/2026 | 12/8/2026 | Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. | |
| Pendiente de análisis | Media (5.3) | 0.52% | — | Cpanel Nova PluginAI | 8/5/2026 | 17/6/2026 | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home… | |
| Analizada | Crítica (9.3) | 99% | ⚠ Explotación activa | CpanelCpanel WHMCpanel WP Squared | 29/4/2026 | 30/9/2026 | cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. | |
| Analizada | Alta (8.8) | 0.83% | — | Cpanel | 11/12/2025 | 17/6/2026 | An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user. | |
| Aplazada | Media (5.6) | 0.44% | — | Cpanel Json XSAI | 8/9/2025 | 17/6/2026 | Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact | |
| Aplazada | Media (5.5) | 0.19% | — | Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAI | 27/2/2025 | 17/6/2026 | Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux)… | |
| Aplazada | Alta (7.1) | 0.17% | — | Digitimber Cpanel IntegrationAI | 3/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DigiTimber DigiTimber cPanel Integration digitimber-cpanel-integration allows Stored XSS.This issue affects DigiTimber cPanel Integration: from n/a through <= 1.4.6. | |
| Aplazada | Baja (3.3) | 0.21% | — | Acronis Backup Plugin FOR Cpanel AND WHMAI | 11/11/2024 | 17/6/2026 | Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892. | |
| Aplazada | Media (5.5) | 0.20% | — | Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAIAcronis Backup Plugin FOR DirectadminAI | 11/11/2024 | 17/6/2026 | Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAIAcronis Backup Plugin FOR DirectadminAI | 17/9/2024 | 17/6/2026 | Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147. | |
| Modificada | Crítica (9.1) | 0.79% | — | Rurban Cpanel\ | 13/2/2024 | 17/6/2026 | The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service. |