Vulnerabilidades en Webpros
38 resultadosAnálisis Vexday
A Webpros possui apenas 1 vulnerabilidade crítica registrada, sem exploração ativa conhecida no momento. A fraqueza dominante (CWE-522 - Armazenamento Insuficiente de Senhas) foi recentemente divulgada, exigindo atenção imediata na validação e remedição, embora o volume reduzido de CVEs sugira menor pressão de ataque comparado a fornecedores maiores.
CVE-2026-68489HIGHStatic Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to executEPSS 0.4%CVE-2026-65646CRITICALImproper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arEPSS 0.4%CVE-2026-58046CRITICALImproper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitraEPSS 0.4%CVE-2026-64639CRITICALIncorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) toEPSS 0.3%CVE-2026-68491CRITICALAn insufficient check allowed for the overwrite of arbitrary files via a symlink.EPSS 0.3%CVE-2026-67402CRITICALAn insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual hoEPSS 0.3%CVE-2026-29204CRITICALInsufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` EPSS 0.3%CVE-2026-32999CRITICALInsufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute EPSS 0.3%CVE-2026-29206HIGHInsufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow QueryEPSS 0.3%CVE-2026-32993HIGHImproper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arEPSS 0.3%CVE-2026-29200CRITICALA critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerabilitEPSS 0.3%CVE-2026-67398HIGHMissing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9EPSS 0.3%CVE-2026-64637CRITICALImproper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative sessiEPSS 0.3%CVE-2026-32992HIGHSSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and captureEPSS 0.3%CVE-2026-64636HIGHAn SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data froEPSS 0.3%CVE-2026-68488CRITICALA Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to rootEPSS 0.2%CVE-2026-32991HIGHImproper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.EPSS 0.2%CVE-2026-67397HIGHPath traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.EPSS 0.1%