Vulnerabilities (CVE)

Filtered by vendor Cpanel Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18471 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
CVE-2017-18472 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
CVE-2017-18481 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
CVE-2016-10856 1 Cpanel 1 Cpanel 2019-08-06 4.0 MEDIUM 6.5 MEDIUM
cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
CVE-2017-18454 1 Cpanel 1 Cpanel 2019-08-06 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
CVE-2018-20874 1 Cpanel 1 Cpanel 2019-08-06 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).
CVE-2018-20891 1 Cpanel 1 Cpanel 2019-08-06 4.9 MEDIUM 5.5 MEDIUM
cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
CVE-2016-10813 1 Cpanel 1 Cpanel 2019-08-06 3.5 LOW 5.4 MEDIUM
cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).
CVE-2017-18385 1 Cpanel 1 Cpanel 2019-08-06 2.1 LOW 5.5 MEDIUM
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
CVE-2016-10851 1 Cpanel 1 Cpanel 2019-08-06 3.5 LOW 5.4 MEDIUM
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
CVE-2018-20900 1 Cpanel 1 Cpanel 2019-08-06 4.3 MEDIUM 6.1 MEDIUM
cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).
CVE-2016-10854 1 Cpanel 1 Cpanel 2019-08-06 3.5 LOW 5.4 MEDIUM
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
CVE-2016-10815 1 Cpanel 1 Cpanel 2019-08-06 4.0 MEDIUM 6.5 MEDIUM
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
CVE-2016-10818 1 Cpanel 1 Cpanel 2019-08-06 4.0 MEDIUM 6.5 MEDIUM
cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
CVE-2016-10819 1 Cpanel 1 Cpanel 2019-08-06 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
CVE-2016-10821 1 Cpanel 1 Cpanel 2019-08-06 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).
CVE-2017-18440 1 Cpanel 1 Cpanel 2019-08-06 4.0 MEDIUM 4.3 MEDIUM
cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).
CVE-2017-18453 1 Cpanel 1 Cpanel 2019-08-06 4.0 MEDIUM 4.9 MEDIUM
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
CVE-2017-18451 1 Cpanel 1 Cpanel 2019-08-06 5.0 MEDIUM 5.3 MEDIUM
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
CVE-2017-18417 1 Cpanel 1 Cpanel 2019-08-05 3.5 LOW 5.4 MEDIUM
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
CVE-2017-18418 1 Cpanel 1 Cpanel 2019-08-05 3.5 LOW 5.4 MEDIUM
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
CVE-2017-18419 1 Cpanel 1 Cpanel 2019-08-05 3.5 LOW 5.4 MEDIUM
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
CVE-2017-18420 1 Cpanel 1 Cpanel 2019-08-05 3.5 LOW 5.4 MEDIUM
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
CVE-2018-20883 1 Cpanel 1 Cpanel 2019-08-02 4.0 MEDIUM 6.5 MEDIUM
cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
CVE-2018-20901 1 Cpanel 1 Cpanel 2019-08-02 4.3 MEDIUM 6.1 MEDIUM
cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).
CVE-2018-20902 1 Cpanel 1 Cpanel 2019-08-02 2.1 LOW 5.5 MEDIUM
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
CVE-2018-20903 1 Cpanel 1 Cpanel 2019-08-02 4.3 MEDIUM 6.1 MEDIUM
cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421).
CVE-2018-20912 1 Cpanel 1 Cpanel 2019-08-02 6.5 MEDIUM 6.3 MEDIUM
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
CVE-2018-20913 1 Cpanel 1 Cpanel 2019-08-02 3.5 LOW 4.9 MEDIUM
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
CVE-2018-20881 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
CVE-2018-20879 1 Cpanel 1 Cpanel 2019-08-01 6.5 MEDIUM 6.3 MEDIUM
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
CVE-2018-20878 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
CVE-2018-20877 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
CVE-2018-20876 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
CVE-2018-20875 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
CVE-2018-20884 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
CVE-2018-20885 1 Cpanel 1 Cpanel 2019-08-01 5.0 MEDIUM 5.3 MEDIUM
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
CVE-2018-20910 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).
CVE-2018-20915 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
CVE-2018-20916 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
CVE-2018-20917 1 Cpanel 1 Cpanel 2019-08-01 2.1 LOW 5.5 MEDIUM
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
CVE-2018-20918 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
CVE-2018-20919 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).
CVE-2018-20920 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).
CVE-2018-20921 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
CVE-2018-20922 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
CVE-2018-20923 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).
CVE-2018-20870 1 Cpanel 1 Cpanel 2019-07-31 2.1 LOW 5.5 MEDIUM
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
CVE-2018-20864 1 Cpanel 1 Cpanel 2019-07-31 6.4 MEDIUM 6.5 MEDIUM
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
CVE-2018-20867 1 Cpanel 1 Cpanel 2019-07-30 5.8 MEDIUM 6.1 MEDIUM
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).