Filtered by vendor Cpanel
Subscribe
Total
426 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-10860 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 5.5 MEDIUM | 8.1 HIGH |
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66). | |||||
CVE-2019-14410 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 2.1 LOW | 3.3 LOW |
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472). | |||||
CVE-2019-14386 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 3.5 LOW | 5.4 MEDIUM |
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504). | |||||
CVE-2016-10848 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 9.0 HIGH | 7.2 HIGH |
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81). | |||||
CVE-2018-20939 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 2.1 LOW | 3.3 LOW |
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339). | |||||
CVE-2018-20912 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 6.5 MEDIUM | 6.3 MEDIUM |
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362). | |||||
CVE-2018-20953 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389). | |||||
CVE-2016-10807 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 4.0 MEDIUM | 6.5 MEDIUM |
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112). | |||||
CVE-2017-18407 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 5.8 MEDIUM | 4.8 MEDIUM |
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279). | |||||
CVE-2017-18411 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 4.0 MEDIUM | 6.8 MEDIUM |
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285). | |||||
CVE-2017-18389 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 6.5 MEDIUM | 6.3 MEDIUM |
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318). | |||||
CVE-2018-20889 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 3.6 LOW | 4.4 MEDIUM |
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425). | |||||
CVE-2016-10836 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 4.0 MEDIUM | 6.5 MEDIUM |
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). | |||||
CVE-2017-18475 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 6.5 MEDIUM | 8.8 HIGH |
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204). | |||||
CVE-2016-10830 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 5.5 MEDIUM | 8.1 HIGH |
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100). | |||||
CVE-2019-14400 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 7.2 HIGH | 7.8 HIGH |
cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479). | |||||
CVE-2019-14409 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466). | |||||
CVE-2017-18424 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 2.1 LOW | 3.3 LOW |
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274). | |||||
CVE-2017-18428 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 1.9 LOW | 2.5 LOW |
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290). | |||||
CVE-2019-14395 | 1 Cpanel | 1 Cpanel | 2023-12-10 | 2.1 LOW | 3.3 LOW |
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494). |