Vulnerabilities (CVE)

Filtered by vendor Cpanel Subscribe
Total 426 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10860 1 Cpanel 1 Cpanel 2023-12-10 5.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
CVE-2019-14410 1 Cpanel 1 Cpanel 2023-12-10 2.1 LOW 3.3 LOW
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
CVE-2019-14386 1 Cpanel 1 Cpanel 2023-12-10 3.5 LOW 5.4 MEDIUM
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
CVE-2016-10848 1 Cpanel 1 Cpanel 2023-12-10 9.0 HIGH 7.2 HIGH
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
CVE-2018-20939 1 Cpanel 1 Cpanel 2023-12-10 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
CVE-2018-20912 1 Cpanel 1 Cpanel 2023-12-10 6.5 MEDIUM 6.3 MEDIUM
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
CVE-2018-20953 1 Cpanel 1 Cpanel 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
CVE-2016-10807 1 Cpanel 1 Cpanel 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).
CVE-2017-18407 1 Cpanel 1 Cpanel 2023-12-10 5.8 MEDIUM 4.8 MEDIUM
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
CVE-2017-18411 1 Cpanel 1 Cpanel 2023-12-10 4.0 MEDIUM 6.8 MEDIUM
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
CVE-2017-18389 1 Cpanel 1 Cpanel 2023-12-10 6.5 MEDIUM 6.3 MEDIUM
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
CVE-2018-20889 1 Cpanel 1 Cpanel 2023-12-10 3.6 LOW 4.4 MEDIUM
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
CVE-2016-10836 1 Cpanel 1 Cpanel 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
CVE-2017-18475 1 Cpanel 1 Cpanel 2023-12-10 6.5 MEDIUM 8.8 HIGH
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).
CVE-2016-10830 1 Cpanel 1 Cpanel 2023-12-10 5.5 MEDIUM 8.1 HIGH
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
CVE-2019-14400 1 Cpanel 1 Cpanel 2023-12-10 7.2 HIGH 7.8 HIGH
cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).
CVE-2019-14409 1 Cpanel 1 Cpanel 2023-12-10 2.1 LOW 5.5 MEDIUM
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
CVE-2017-18424 1 Cpanel 1 Cpanel 2023-12-10 2.1 LOW 3.3 LOW
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
CVE-2017-18428 1 Cpanel 1 Cpanel 2023-12-10 1.9 LOW 2.5 LOW
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
CVE-2019-14395 1 Cpanel 1 Cpanel 2023-12-10 2.1 LOW 3.3 LOW
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).