Vulnerabilidades em Webpros
38 resultadosAnálise Vexday
A Webpros possui apenas 1 vulnerabilidade crítica registrada, sem exploração ativa conhecida no momento. A fraqueza dominante (CWE-522 - Armazenamento Insuficiente de Senhas) foi recentemente divulgada, exigindo atenção imediata na validação e remedição, embora o volume reduzido de CVEs sugira menor pressão de ataque comparado a fornecedores maiores.
CVE-2026-41940CRITICALWebPros cPanel and WHM Authentication Bypass via Login FlowEPSS 98.5%KEVCVE-2026-29205HIGHIncorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment downloaEPSS 8.2%CVE-2026-65638CRITICALImproper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commaEPSS 3.2%CVE-2026-29202MEDIUMInsufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the alEPSS 1.9%CVE-2026-65639CRITICALOS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured alloEPSS 1.6%CVE-2026-67394CRITICALA critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions EPSS 1.3%CVE-2026-67401CRITICALA vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack componentEPSS 1.0%CVE-2026-58048CRITICALImproper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.EPSS 1.0%CVE-2026-65643HIGHEval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.EPSS 0.9%CVE-2026-67399CRITICALDeserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.EPSS 0.8%CVE-2026-44962CRITICALPlesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolatEPSS 0.7%CVE-2026-56843CRITICALIncorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domaiEPSS 0.7%CVE-2026-48614CRITICALAn improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resuEPSS 0.6%CVE-2026-58047MEDIUMHTTP Smuggling in cPanel allows potential leak of credentials.EPSS 0.5%CVE-2026-65647HIGHImproper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.EPSS 0.5%CVE-2026-29203MEDIUMA chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system filEPSS 0.5%CVE-2026-65642HIGHInsecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and EPSS 0.5%CVE-2026-29201HIGHInsufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relaEPSS 0.4%CVE-2026-47365CRITICALArgument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass croEPSS 0.4%CVE-2026-68487CRITICALPath traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.EPSS 0.4%