Skip to main content

Vendor archive

cpanel CVEs

Beta · best-effort

428 CVEs tagged to vendor cpanel21 Critical, 106 High, 244 Medium, 57 Low, 0 Unrated.

CVE-2019-14404

Published Jul 30, 2019

cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14403

Published Jul 30, 2019

cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14402

Published Jul 30, 2019

cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14401

Published Jul 30, 2019

cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14400

Published Jul 30, 2019

cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14399

Published Jul 30, 2019

The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14398

Published Jul 30, 2019

cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14397

Published Jul 30, 2019

cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14396

Published Jul 30, 2019

API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14395

Published Jul 30, 2019

cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14394

Published Jul 30, 2019

cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14393

Published Jul 30, 2019

cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20870

Published Jul 30, 2019

The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20869

Published Jul 30, 2019

cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20868

Published Jul 30, 2019

cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20866

Published Jul 30, 2019

cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20865

Published Jul 30, 2019

cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20864

Published Jul 30, 2019

cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20863

Published Jul 30, 2019

cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-20862

Published Jul 30, 2019

cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14392

Published Jul 30, 2019

cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20867

Published Jul 30, 2019

cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14391

Published Jul 30, 2019

cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14390

Published Jul 30, 2019

cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14389

Published Jul 30, 2019

cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 428 CVEsPage 15 of 18