Vulnerabilities (CVE)

Filtered by vendor Cpanel Subscribe
Filtered by product Cpanel
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14392 1 Cpanel 1 Cpanel 2020-08-24 6.5 MEDIUM 8.8 HIGH
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
CVE-2018-20908 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 5.5 MEDIUM
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
CVE-2019-14411 1 Cpanel 1 Cpanel 2020-08-24 5.0 MEDIUM 5.3 MEDIUM
cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).
CVE-2018-20907 1 Cpanel 1 Cpanel 2020-08-24 4.0 MEDIUM 4.3 MEDIUM
cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).
CVE-2018-20936 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
CVE-2018-20892 1 Cpanel 1 Cpanel 2020-08-24 4.0 MEDIUM 4.3 MEDIUM
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).
CVE-2018-20862 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 7.8 HIGH
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
CVE-2019-14389 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 7.8 HIGH
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
CVE-2018-20926 1 Cpanel 1 Cpanel 2020-08-24 7.2 HIGH 6.7 MEDIUM
cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).
CVE-2019-14400 1 Cpanel 1 Cpanel 2020-08-24 7.2 HIGH 7.8 HIGH
cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).
CVE-2019-20498 1 Cpanel 1 Cpanel 2020-08-24 7.5 HIGH 9.8 CRITICAL
cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
CVE-2018-20906 1 Cpanel 1 Cpanel 2020-08-24 4.0 MEDIUM 4.3 MEDIUM
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).
CVE-2019-14413 1 Cpanel 1 Cpanel 2020-08-24 4.0 MEDIUM 4.3 MEDIUM
cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).
CVE-2019-20492 1 Cpanel 1 Cpanel 2020-08-24 6.5 MEDIUM 8.8 HIGH
cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).
CVE-2019-14402 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 3.3 LOW
cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
CVE-2019-14398 1 Cpanel 1 Cpanel 2020-08-24 6.5 MEDIUM 8.8 HIGH
cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).
CVE-2019-14405 1 Cpanel 1 Cpanel 2020-08-24 6.5 MEDIUM 8.8 HIGH
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
CVE-2019-14414 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 3.3 LOW
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
CVE-2018-20905 1 Cpanel 1 Cpanel 2020-08-24 5.5 MEDIUM 5.4 MEDIUM
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
CVE-2019-20490 1 Cpanel 1 Cpanel 2020-08-24 6.5 MEDIUM 8.8 HIGH
cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
CVE-2018-20886 1 Cpanel 1 Cpanel 2020-08-24 4.6 MEDIUM 5.3 MEDIUM
cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
CVE-2018-20880 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 3.3 LOW
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
CVE-2019-20491 1 Cpanel 1 Cpanel 2020-08-24 5.5 MEDIUM 5.4 MEDIUM
cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).
CVE-2019-14401 1 Cpanel 1 Cpanel 2020-08-24 6.5 MEDIUM 8.8 HIGH
cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).
CVE-2019-14396 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 3.3 LOW
API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
CVE-2018-20909 1 Cpanel 1 Cpanel 2020-08-24 3.6 LOW 7.1 HIGH
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).
CVE-2019-14388 1 Cpanel 1 Cpanel 2020-08-24 5.0 MEDIUM 7.5 HIGH
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
CVE-2019-14391 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 3.3 LOW
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
CVE-2019-20496 1 Cpanel 1 Cpanel 2020-03-19 4.9 MEDIUM 5.5 MEDIUM
cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
CVE-2019-20497 1 Cpanel 1 Cpanel 2020-03-19 3.5 LOW 5.4 MEDIUM
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
CVE-2020-10113 1 Cpanel 1 Cpanel 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).
CVE-2020-10114 1 Cpanel 1 Cpanel 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
CVE-2020-10118 1 Cpanel 1 Cpanel 2020-03-19 6.4 MEDIUM 9.1 CRITICAL
cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).
CVE-2020-10121 1 Cpanel 1 Cpanel 2020-03-19 7.5 HIGH 9.8 CRITICAL
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
CVE-2020-10119 1 Cpanel 1 Cpanel 2020-03-19 7.5 HIGH 9.8 CRITICAL
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
CVE-2019-20493 1 Cpanel 1 Cpanel 2020-03-18 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
CVE-2012-6449 1 Cpanel 2 Cpanel, Whm 2020-02-13 3.5 LOW 5.4 MEDIUM
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
CVE-2017-5614 1 Cpanel 1 Cpanel 2019-10-31 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.
CVE-2019-17375 1 Cpanel 1 Cpanel 2019-10-11 6.5 MEDIUM 8.8 HIGH
cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).
CVE-2019-17378 1 Cpanel 1 Cpanel 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
CVE-2019-17377 1 Cpanel 1 Cpanel 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
CVE-2019-17379 1 Cpanel 1 Cpanel 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
CVE-2019-17376 1 Cpanel 1 Cpanel 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
CVE-2019-17380 1 Cpanel 1 Cpanel 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
CVE-2017-18429 1 Cpanel 1 Cpanel 2019-09-24 2.1 LOW 3.3 LOW
In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
CVE-2017-18452 1 Cpanel 1 Cpanel 2019-08-14 4.6 MEDIUM 6.7 MEDIUM
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
CVE-2017-18446 1 Cpanel 1 Cpanel 2019-08-14 6.5 MEDIUM 6.3 MEDIUM
cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).
CVE-2017-18400 1 Cpanel 1 Cpanel 2019-08-13 7.2 HIGH 7.8 HIGH
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).
CVE-2017-18399 1 Cpanel 1 Cpanel 2019-08-13 4.3 MEDIUM 3.7 LOW
cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332).
CVE-2017-18398 1 Cpanel 1 Cpanel 2019-08-13 5.5 MEDIUM 3.8 LOW
DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).