Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18434 1 Cpanel 1 Cpanel 2019-08-09 7.2 HIGH 7.8 HIGH
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).
CVE-2017-18435 1 Cpanel 1 Cpanel 2019-08-09 7.5 HIGH 7.3 HIGH
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
CVE-2017-18436 1 Cpanel 1 Cpanel 2019-08-09 2.7 LOW 3.5 LOW
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
CVE-2019-7889 1 Magento 1 Magento 2019-08-09 4.0 MEDIUM 6.5 MEDIUM
An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with marketing manipulation privileges can invoke methods that alter data of the underlying model followed by corresponding database modifications.
CVE-2019-13108 1 Exiv2 1 Exiv2 2019-08-09 4.3 MEDIUM 6.5 MEDIUM
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset.
CVE-2019-13109 1 Exiv2 1 Exiv2 2019-08-09 4.3 MEDIUM 6.5 MEDIUM
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.
CVE-2019-13111 1 Exiv2 1 Exiv2 2019-08-09 4.3 MEDIUM 5.5 MEDIUM
A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.
CVE-2019-7897 1 Magento 1 Magento 2019-08-09 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to customer configurations to inject malicious javascript.
CVE-2019-7898 1 Magento 1 Magento 2019-08-09 5.0 MEDIUM 5.3 MEDIUM
Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to inadequate validation of user input.
CVE-2019-7899 1 Magento 1 Magento 2019-08-09 5.0 MEDIUM 5.3 MEDIUM
Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
CVE-2019-7909 1 Magento 1 Magento 2019-08-09 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to email templates.
CVE-2019-7911 1 Magento 1 Magento 2019-08-09 6.5 MEDIUM 7.2 HIGH
A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to the admin panel to manipulate system configuration and execute arbitrary code.
CVE-2019-7912 1 Magento 1 Magento 2019-08-09 6.5 MEDIUM 7.2 HIGH
A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to edit configuration keys to remove file extension filters, potentially resulting in the malicious upload and execution of malicious files on the server.
CVE-2019-7947 1 Magento 1 Magento 2019-08-09 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
CVE-2019-5460 1 Videolan 1 Vlc Media Player 2019-08-08 4.3 MEDIUM 5.5 MEDIUM
Double Free in VLC versions <= 3.0.6 leads to a crash.
CVE-2017-18469 1 Cpanel 1 Cpanel 2019-08-08 6.5 MEDIUM 6.3 MEDIUM
cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).
CVE-2016-10785 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 6.5 MEDIUM
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
CVE-2017-18456 1 Cpanel 1 Cpanel 2019-08-08 4.3 MEDIUM 6.1 MEDIUM
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
CVE-2018-20947 1 Cpanel 1 Cpanel 2019-08-08 2.1 LOW 5.5 MEDIUM
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
CVE-2018-20952 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 6.5 MEDIUM
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
CVE-2016-10845 1 Cpanel 1 Cpanel 2019-08-08 6.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).
CVE-2018-20953 1 Cpanel 1 Cpanel 2019-08-08 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
CVE-2016-10846 1 Cpanel 1 Cpanel 2019-08-08 8.5 HIGH 8.1 HIGH
cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).
CVE-2016-10843 1 Cpanel 1 Cpanel 2019-08-08 5.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).
CVE-2016-10768 1 Cpanel 1 Cpanel 2019-08-08 5.5 MEDIUM 6.5 MEDIUM
cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).
CVE-2016-10769 1 Cpanel 1 Cpanel 2019-08-08 5.8 MEDIUM 6.1 MEDIUM
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
CVE-2016-10776 1 Cpanel 1 Cpanel 2019-08-08 3.5 LOW 5.4 MEDIUM
cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).
CVE-2016-10777 1 Cpanel 1 Cpanel 2019-08-08 3.5 LOW 5.4 MEDIUM
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).
CVE-2016-10780 1 Cpanel 1 Cpanel 2019-08-08 3.5 LOW 5.4 MEDIUM
cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).
CVE-2016-10778 1 Cpanel 1 Cpanel 2019-08-08 3.5 LOW 5.4 MEDIUM
cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).
CVE-2016-10781 1 Cpanel 1 Cpanel 2019-08-08 3.5 LOW 5.4 MEDIUM
cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).
CVE-2016-10782 1 Cpanel 1 Cpanel 2019-08-08 3.5 LOW 5.4 MEDIUM
cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).
CVE-2016-10783 1 Cpanel 1 Cpanel 2019-08-08 3.5 LOW 5.4 MEDIUM
cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).
CVE-2016-10784 1 Cpanel 1 Cpanel 2019-08-08 3.5 LOW 5.4 MEDIUM
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
CVE-2018-20941 1 Cpanel 1 Cpanel 2019-08-08 4.7 MEDIUM 5.6 MEDIUM
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
CVE-2018-20929 1 Cpanel 1 Cpanel 2019-08-08 5.8 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
CVE-2018-20928 1 Cpanel 1 Cpanel 2019-08-08 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391).
CVE-2016-10837 1 Cpanel 1 Cpanel 2019-08-08 8.5 HIGH 7.5 HIGH
cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).
CVE-2018-20924 1 Cpanel 1 Cpanel 2019-08-08 7.5 HIGH 5.5 MEDIUM
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
CVE-2018-20890 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 4.3 MEDIUM
cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).
CVE-2013-2157 1 Openstack 1 Keystone 2019-08-08 4.3 MEDIUM N/A
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
CVE-2016-10844 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 6.5 MEDIUM
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
CVE-2018-20882 1 Cpanel 1 Cpanel 2019-08-08 6.6 MEDIUM 6.8 MEDIUM
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).
CVE-2016-10848 1 Cpanel 1 Cpanel 2019-08-08 9.0 HIGH 7.2 HIGH
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
CVE-2016-10847 1 Cpanel 1 Cpanel 2019-08-08 5.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
CVE-2016-10841 1 Cpanel 1 Cpanel 2019-08-08 2.1 LOW 5.3 MEDIUM
The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73).
CVE-2018-20897 1 Cpanel 1 Cpanel 2019-08-08 3.3 LOW 2.8 LOW
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
CVE-2018-20899 1 Cpanel 1 Cpanel 2019-08-08 4.3 MEDIUM 6.1 MEDIUM
cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).
CVE-2017-18389 1 Cpanel 1 Cpanel 2019-08-08 6.5 MEDIUM 6.3 MEDIUM
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
CVE-2014-0130 2 Redhat, Rubyonrails 3 Subscription Asset Manager, Rails, Ruby On Rails 2019-08-08 4.3 MEDIUM N/A
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.