Vulnerabilities (CVE)

Filtered by vendor Cpanel Subscribe
Total 426 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18435 1 Cpanel 1 Cpanel 2024-02-04 7.5 HIGH 7.3 HIGH
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
CVE-2019-14395 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 3.3 LOW
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
CVE-2018-20923 1 Cpanel 1 Cpanel 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).
CVE-2017-18389 1 Cpanel 1 Cpanel 2024-02-04 6.5 MEDIUM 6.3 MEDIUM
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
CVE-2017-18412 1 Cpanel 1 Cpanel 2024-02-04 1.9 LOW 2.5 LOW
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
CVE-2018-20906 1 Cpanel 1 Cpanel 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).
CVE-2017-18451 1 Cpanel 1 Cpanel 2024-02-04 5.0 MEDIUM 5.3 MEDIUM
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
CVE-2018-20870 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 5.5 MEDIUM
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
CVE-2018-20946 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
CVE-2017-18466 1 Cpanel 1 Cpanel 2024-02-04 4.0 MEDIUM 2.7 LOW
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228).
CVE-2016-10848 1 Cpanel 1 Cpanel 2024-02-04 9.0 HIGH 7.2 HIGH
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
CVE-2018-20939 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
CVE-2016-10820 1 Cpanel 1 Cpanel 2024-02-04 9.0 HIGH 8.8 HIGH
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
CVE-2017-18453 1 Cpanel 1 Cpanel 2024-02-04 4.0 MEDIUM 4.9 MEDIUM
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
CVE-2018-20948 1 Cpanel 1 Cpanel 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
CVE-2017-18450 1 Cpanel 1 Cpanel 2024-02-04 4.4 MEDIUM 4.5 MEDIUM
cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
CVE-2016-10816 1 Cpanel 1 Cpanel 2024-02-04 6.5 MEDIUM 8.8 HIGH
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
CVE-2017-18442 1 Cpanel 1 Cpanel 2024-02-04 5.0 MEDIUM 5.3 MEDIUM
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
CVE-2019-14409 1 Cpanel 1 Cpanel 2024-02-04 2.1 LOW 5.5 MEDIUM
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
CVE-2016-10845 1 Cpanel 1 Cpanel 2024-02-04 6.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).