Vulnerabilities (CVE)

Filtered by vendor Cpanel Subscribe
Total 426 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20922 1 Cpanel 1 Cpanel 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
CVE-2017-18457 1 Cpanel 1 Cpanel 2024-02-04 4.9 MEDIUM 4.4 MEDIUM
cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218).
CVE-2016-10818 1 Cpanel 1 Cpanel 2024-02-04 4.0 MEDIUM 6.5 MEDIUM
cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
CVE-2016-10788 1 Cpanel 1 Cpanel 2024-02-04 9.0 HIGH 8.8 HIGH
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
CVE-2018-20933 1 Cpanel 1 Cpanel 2024-02-04 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
CVE-2017-18443 1 Cpanel 1 Cpanel 2024-02-04 5.0 MEDIUM 5.8 MEDIUM
cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).
CVE-2018-20880 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 3.3 LOW
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
CVE-2016-10768 1 Cpanel 1 Cpanel 2024-02-04 5.5 MEDIUM 6.5 MEDIUM
cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).
CVE-2018-20897 1 Cpanel 1 Cpanel 2024-02-04 3.3 LOW 2.8 LOW
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
CVE-2017-18447 1 Cpanel 1 Cpanel 2024-02-04 6.5 MEDIUM 6.3 MEDIUM
cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).
CVE-2017-18472 1 Cpanel 1 Cpanel 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
CVE-2018-20916 1 Cpanel 1 Cpanel 2024-02-04 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
CVE-2017-18419 1 Cpanel 1 Cpanel 2024-02-04 3.5 LOW 5.4 MEDIUM
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
CVE-2016-10825 1 Cpanel 1 Cpanel 2024-02-04 5.5 MEDIUM 8.1 HIGH
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
CVE-2017-18420 1 Cpanel 1 Cpanel 2024-02-04 3.5 LOW 5.4 MEDIUM
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
CVE-2017-18399 1 Cpanel 1 Cpanel 2024-02-04 4.3 MEDIUM 3.7 LOW
cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332).
CVE-2018-20950 1 Cpanel 1 Cpanel 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
CVE-2017-18387 1 Cpanel 1 Cpanel 2024-02-04 9.0 HIGH 7.2 HIGH
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
CVE-2017-18481 1 Cpanel 1 Cpanel 2024-02-04 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
CVE-2018-20863 1 Cpanel 1 Cpanel 2024-02-04 7.5 HIGH 9.8 CRITICAL
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).