Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Cpanel Subscribe
Filtered by product Cpanel
Total 416 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14395 1 Cpanel 1 Cpanel 2021-07-21 2.1 LOW 3.3 LOW
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
CVE-2020-26105 1 Cpanel 1 Cpanel 2021-07-21 5.0 MEDIUM 9.8 CRITICAL
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
CVE-2020-10115 1 Cpanel 1 Cpanel 2021-07-21 9.0 HIGH 7.2 HIGH
cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
CVE-2019-20494 1 Cpanel 1 Cpanel 2021-07-21 2.1 LOW 3.3 LOW
In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).
CVE-2020-10116 1 Cpanel 1 Cpanel 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541).
CVE-2020-10117 1 Cpanel 1 Cpanel 2021-07-21 6.4 MEDIUM 9.1 CRITICAL
cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).
CVE-2019-14407 1 Cpanel 1 Cpanel 2021-07-21 4.0 MEDIUM 2.7 LOW
cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
CVE-2020-29135 1 Cpanel 1 Cpanel 2021-07-21 3.5 LOW 4.1 MEDIUM
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
CVE-2019-14399 1 Cpanel 1 Cpanel 2021-07-21 6.1 MEDIUM 7.1 HIGH
The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).
CVE-2021-31803 1 Cpanel 1 Cpanel 2021-05-06 4.3 MEDIUM 6.1 MEDIUM
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
CVE-2021-26266 1 Cpanel 1 Cpanel 2021-02-03 5.0 MEDIUM 7.5 HIGH
cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).
CVE-2021-26267 1 Cpanel 1 Cpanel 2021-02-03 5.0 MEDIUM 7.5 HIGH
cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).
CVE-2020-29137 1 Cpanel 1 Cpanel 2020-12-01 4.3 MEDIUM 6.1 MEDIUM
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
CVE-2020-26099 1 Cpanel 1 Cpanel 2020-09-29 5.0 MEDIUM 7.5 HIGH
cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
CVE-2020-26098 1 Cpanel 1 Cpanel 2020-09-29 7.5 HIGH 9.8 CRITICAL
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
CVE-2020-26100 1 Cpanel 1 Cpanel 2020-09-29 7.5 HIGH 9.8 CRITICAL
chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
CVE-2020-26104 1 Cpanel 1 Cpanel 2020-09-29 5.0 MEDIUM 7.5 HIGH
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
CVE-2020-26103 1 Cpanel 1 Cpanel 2020-09-29 5.0 MEDIUM 7.5 HIGH
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
CVE-2020-26109 1 Cpanel 1 Cpanel 2020-09-29 5.0 MEDIUM 7.5 HIGH
cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557).
CVE-2020-26108 1 Cpanel 1 Cpanel 2020-09-29 7.5 HIGH 9.8 CRITICAL
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).