Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.2
CVE-2026-32992
- EPSS 0.25%
- Veröffentlicht 13.05.2026 22:16:43
- Zuletzt bearbeitet 12.08.2026 18:40:47
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
8.6
CVE-2026-29205
- EPSS 8.15%
- Veröffentlicht 13.05.2026 22:16:42
- Zuletzt bearbeitet 12.08.2026 18:34:24
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
9.8
CVE-2026-41940
- EPSS 97.93%
- Veröffentlicht 29.04.2026 15:10:37
- Zuletzt bearbeitet 04.05.2026 18:09:42
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
1