Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Cpanel Subscribe
Total 425 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18448 1 Cpanel 1 Cpanel 2019-08-08 5.0 MEDIUM 5.3 MEDIUM
cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
CVE-2017-18449 1 Cpanel 1 Cpanel 2019-08-08 2.1 LOW 5.5 MEDIUM
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).
CVE-2017-18450 1 Cpanel 1 Cpanel 2019-08-08 4.4 MEDIUM 4.5 MEDIUM
cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
CVE-2017-18461 1 Cpanel 1 Cpanel 2019-08-08 5.0 MEDIUM 4.3 MEDIUM
cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223).
CVE-2017-18455 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 2.7 LOW
In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).
CVE-2017-18430 1 Cpanel 1 Cpanel 2019-08-08 4.6 MEDIUM 4.7 MEDIUM
In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).
CVE-2017-18445 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 4.3 MEDIUM
cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).
CVE-2017-18444 1 Cpanel 1 Cpanel 2019-08-08 5.0 MEDIUM 5.3 MEDIUM
cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
CVE-2017-18460 1 Cpanel 1 Cpanel 2019-08-07 7.2 HIGH 7.8 HIGH
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
CVE-2017-18459 1 Cpanel 1 Cpanel 2019-08-07 7.2 HIGH 7.8 HIGH
cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).
CVE-2017-18442 1 Cpanel 1 Cpanel 2019-08-07 5.0 MEDIUM 5.3 MEDIUM
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
CVE-2017-18441 1 Cpanel 1 Cpanel 2019-08-07 4.0 MEDIUM 5.0 MEDIUM
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
CVE-2018-20951 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).
CVE-2018-20950 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
CVE-2018-20949 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
CVE-2018-20948 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
CVE-2018-20946 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
CVE-2018-20944 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
CVE-2018-20940 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).
CVE-2018-20939 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).