Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Cpanel Subscribe
Filtered by product Cpanel
Total 416 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10824 1 Cpanel 1 Cpanel 2019-08-07 9.3 HIGH 9.8 CRITICAL
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
CVE-2018-20888 1 Cpanel 1 Cpanel 2019-08-07 4.9 MEDIUM 5.5 MEDIUM
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
CVE-2016-10823 1 Cpanel 1 Cpanel 2019-08-07 9.0 HIGH 8.8 HIGH
cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).
CVE-2018-20933 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
CVE-2018-20889 1 Cpanel 1 Cpanel 2019-08-07 3.6 LOW 4.4 MEDIUM
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
CVE-2018-20894 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
CVE-2018-20895 1 Cpanel 1 Cpanel 2019-08-07 6.5 MEDIUM 7.2 HIGH
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
CVE-2018-20896 1 Cpanel 1 Cpanel 2019-08-07 3.3 LOW 3.9 LOW
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
CVE-2015-9291 1 Cpanel 1 Cpanel 2019-08-07 5.0 MEDIUM 7.5 HIGH
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
CVE-2016-10827 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
CVE-2016-10822 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).
CVE-2018-20935 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).
CVE-2017-18473 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
CVE-2017-18471 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
CVE-2017-18472 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
CVE-2017-18481 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
CVE-2016-10856 1 Cpanel 1 Cpanel 2019-08-06 4.0 MEDIUM 6.5 MEDIUM
cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
CVE-2017-18463 1 Cpanel 1 Cpanel 2019-08-06 7.2 HIGH 7.8 HIGH
cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).
CVE-2017-18458 1 Cpanel 1 Cpanel 2019-08-06 3.6 LOW 3.3 LOW
cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
CVE-2017-18454 1 Cpanel 1 Cpanel 2019-08-06 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).