Vulnerabilities (CVE)

Filtered by vendor Cpanel Subscribe
Filtered by product Cpanel
Total 417 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14408 1 Cpanel 1 Cpanel 2020-08-24 4.0 MEDIUM 4.3 MEDIUM
cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).
CVE-2019-14396 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 3.3 LOW
API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
CVE-2019-14411 1 Cpanel 1 Cpanel 2020-08-24 5.0 MEDIUM 5.3 MEDIUM
cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).
CVE-2018-20905 1 Cpanel 1 Cpanel 2020-08-24 5.5 MEDIUM 5.4 MEDIUM
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
CVE-2019-14392 1 Cpanel 1 Cpanel 2020-08-24 6.5 MEDIUM 8.8 HIGH
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
CVE-2018-20862 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 7.8 HIGH
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
CVE-2018-20926 1 Cpanel 1 Cpanel 2020-08-24 7.2 HIGH 6.7 MEDIUM
cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).
CVE-2019-20491 1 Cpanel 1 Cpanel 2020-08-24 5.5 MEDIUM 5.4 MEDIUM
cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).
CVE-2018-20909 1 Cpanel 1 Cpanel 2020-08-24 3.6 LOW 7.1 HIGH
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).
CVE-2019-14414 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 3.3 LOW
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
CVE-2018-20892 1 Cpanel 1 Cpanel 2020-08-24 4.0 MEDIUM 4.3 MEDIUM
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).
CVE-2019-14397 1 Cpanel 1 Cpanel 2020-08-24 5.0 MEDIUM 5.3 MEDIUM
cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).
CVE-2018-20880 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 3.3 LOW
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
CVE-2019-14398 1 Cpanel 1 Cpanel 2020-08-24 6.5 MEDIUM 8.8 HIGH
cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).
CVE-2018-20908 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 5.5 MEDIUM
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
CVE-2019-14393 1 Cpanel 1 Cpanel 2020-08-24 4.6 MEDIUM 5.3 MEDIUM
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).
CVE-2018-20907 1 Cpanel 1 Cpanel 2020-08-24 4.0 MEDIUM 4.3 MEDIUM
cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).
CVE-2019-14405 1 Cpanel 1 Cpanel 2020-08-24 6.5 MEDIUM 8.8 HIGH
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
CVE-2019-14389 1 Cpanel 1 Cpanel 2020-08-24 2.1 LOW 7.8 HIGH
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
CVE-2019-14388 1 Cpanel 1 Cpanel 2020-08-24 5.0 MEDIUM 7.5 HIGH
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).