Vulnerabilities (CVE)

Filtered by vendor Cpanel Subscribe
Filtered by product Cpanel
Total 417 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18422 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 3.3 LOW
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
CVE-2017-18395 1 Cpanel 1 Cpanel 2024-02-04 4.0 MEDIUM 2.7 LOW
cPanel before 68.0.15 does not block a username of ssl (SEC-328).
CVE-2017-18421 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 3.3 LOW
cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
CVE-2018-20892 1 Cpanel 1 Cpanel 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).
CVE-2018-20932 1 Cpanel 1 Cpanel 2024-02-04 4.0 MEDIUM 2.7 LOW
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
CVE-2018-20904 1 Cpanel 1 Cpanel 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427).
CVE-2017-18449 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 5.5 MEDIUM
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).
CVE-2018-20868 1 Cpanel 1 Cpanel 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
CVE-2018-20879 1 Cpanel 1 Cpanel 2024-02-04 6.5 MEDIUM 6.3 MEDIUM
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
CVE-2017-18475 1 Cpanel 1 Cpanel 2024-02-04 6.5 MEDIUM 8.8 HIGH
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).
CVE-2016-10806 1 Cpanel 1 Cpanel 2024-02-04 3.5 LOW 5.4 MEDIUM
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).
CVE-2017-18435 1 Cpanel 1 Cpanel 2024-02-04 7.5 HIGH 7.3 HIGH
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
CVE-2019-14395 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 3.3 LOW
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
CVE-2018-20923 1 Cpanel 1 Cpanel 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).
CVE-2017-18389 1 Cpanel 1 Cpanel 2024-02-04 6.5 MEDIUM 6.3 MEDIUM
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
CVE-2017-18412 1 Cpanel 1 Cpanel 2024-02-04 1.9 LOW 2.5 LOW
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
CVE-2018-20906 1 Cpanel 1 Cpanel 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).
CVE-2017-18451 1 Cpanel 1 Cpanel 2024-02-04 5.0 MEDIUM 5.3 MEDIUM
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
CVE-2018-20870 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 5.5 MEDIUM
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
CVE-2018-20946 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).