Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20902 1 Cpanel 1 Cpanel 2019-08-02 2.1 LOW 5.5 MEDIUM
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
CVE-2018-20903 1 Cpanel 1 Cpanel 2019-08-02 4.3 MEDIUM 6.1 MEDIUM
cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421).
CVE-2018-20912 1 Cpanel 1 Cpanel 2019-08-02 6.5 MEDIUM 6.3 MEDIUM
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
CVE-2018-20913 1 Cpanel 1 Cpanel 2019-08-02 3.5 LOW 4.9 MEDIUM
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
CVE-2018-20881 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
CVE-2018-20879 1 Cpanel 1 Cpanel 2019-08-01 6.5 MEDIUM 6.3 MEDIUM
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
CVE-2018-20878 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
CVE-2018-20877 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
CVE-2018-20876 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
CVE-2018-20875 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
CVE-2018-20884 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
CVE-2018-20885 1 Cpanel 1 Cpanel 2019-08-01 5.0 MEDIUM 5.3 MEDIUM
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
CVE-2018-20910 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).
CVE-2018-20915 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
CVE-2018-20916 1 Cpanel 1 Cpanel 2019-08-01 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
CVE-2018-20917 1 Cpanel 1 Cpanel 2019-08-01 2.1 LOW 5.5 MEDIUM
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
CVE-2018-20918 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
CVE-2018-20919 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).
CVE-2018-20920 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).
CVE-2018-20921 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
CVE-2018-20922 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
CVE-2018-20923 1 Cpanel 1 Cpanel 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).
CVE-2019-1020005 1 Inveniosoftware 1 Invenio-communities 2019-08-01 3.5 LOW 5.4 MEDIUM
invenio-communities before 1.0.0a20 allows XSS.
CVE-2019-13607 1 Opera 1 Mini 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
The Opera Mini application through 16.0.14 for iOS has a UXSS vulnerability that can be triggered by performing navigation to a javascript: URL.
CVE-2019-1020003 1 Inveniosoftware 1 Invenio-records 2019-08-01 3.5 LOW 5.4 MEDIUM
invenio-records before 1.2.2 allows XSS.
CVE-2019-1020006 1 Inveniosoftware 1 Invenio-app 2019-08-01 5.8 MEDIUM 6.1 MEDIUM
invenio-app before 1.1.1 allows host header injection.
CVE-2019-1020016 1 Ash-aio Project 1 Ash-aio 2019-08-01 5.8 MEDIUM 6.1 MEDIUM
ASH-AIO before 2.0.0.3 allows an open redirect.
CVE-2015-9288 1 Unity 1 Web Player 2019-08-01 4.0 MEDIUM 6.5 MEDIUM
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials
CVE-2019-13584 1 Fanucamerica 1 Robotics Virtual Robot Controller 2019-08-01 5.0 MEDIUM 5.3 MEDIUM
The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request.
CVE-2018-14037 1 Progress 1 Kendo Ui 2019-08-01 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Serializer toEditableHtml function in kendo.all.min.js. If the victim accesses the editor, the payload gets executed. Furthermore, if the payload is reflected at any other resource that does rely on the sanitisation of the editor itself, the JavaScript payload will be executed in the context of the application. This allows attackers (in the worst case) to take over user sessions.
CVE-2019-1020019 1 Inveniosoftware 1 Invenio-previewer 2019-07-31 4.3 MEDIUM 6.1 MEDIUM
invenio-previewer before 1.0.0a12 allows XSS.
CVE-2019-14327 1 Custom Simple Rss Project 1 Custom Simple Rss 2019-07-31 4.3 MEDIUM 6.5 MEDIUM
A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings.
CVE-2019-1020008 1 Stacktable.js Project 1 Stacktable.js 2019-07-31 4.3 MEDIUM 6.1 MEDIUM
stacktable.js before 1.0.4 allows XSS.
CVE-2019-14286 1 Misp 1 Misp 2019-07-31 4.3 MEDIUM 6.1 MEDIUM
In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view. A malicious MISP event must be crafted in order to trigger the vulnerability.
CVE-2019-7280 1 Primasystems 1 Flexair 2019-07-31 4.0 MEDIUM 4.3 MEDIUM
Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.
CVE-2018-20870 1 Cpanel 1 Cpanel 2019-07-31 2.1 LOW 5.5 MEDIUM
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
CVE-2018-20864 1 Cpanel 1 Cpanel 2019-07-31 6.4 MEDIUM 6.5 MEDIUM
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
CVE-2019-10263 1 Ahsay 1 Cloud Backup Suite 2019-07-31 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrieve the admin's cookie and take over the account.
CVE-2019-13414 1 Boiteasite 1 Rencontre 2019-07-31 4.3 MEDIUM 6.1 MEDIUM
The Rencontre plugin before 3.1.3 for WordPress allows XSS via inc/rencontre_widget.php.
CVE-2019-6002 1 Central Dogma Project 1 Central Dogma 2019-07-31 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-1000169 1 Jenkins 1 Jenkins 2019-07-31 5.0 MEDIUM 5.3 MEDIUM
An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler.java that allows unauthorized attackers to confirm the existence of agents or views with an attacker-specified name by sending a CLI command to Jenkins.
CVE-2019-11727 1 Mozilla 1 Firefox 2019-07-30 5.0 MEDIUM 5.3 MEDIUM
A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.
CVE-2018-20867 1 Cpanel 1 Cpanel 2019-07-30 5.8 MEDIUM 6.1 MEDIUM
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
CVE-2019-14403 1 Cpanel 1 Cpanel 2019-07-30 4.3 MEDIUM 4.3 MEDIUM
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
CVE-2018-20866 1 Cpanel 1 Cpanel 2019-07-30 4.3 MEDIUM 6.1 MEDIUM
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
CVE-2018-20868 1 Cpanel 1 Cpanel 2019-07-30 4.3 MEDIUM 6.1 MEDIUM
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
CVE-2018-19311 1 Centreon 1 Centreon 2019-07-30 3.5 LOW 5.4 MEDIUM
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.
CVE-2018-19280 1 Centreon 1 Centreon 2019-07-30 4.3 MEDIUM 6.1 MEDIUM
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.
CVE-2015-7672 1 Centreon 1 Centreon 2019-07-30 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).
CVE-2019-14406 1 Cpanel 1 Cpanel 2019-07-30 4.3 MEDIUM 6.1 MEDIUM
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).