Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18445 | Med | 0.28 | 4.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249). | ||
| CVE-2017-18440 | Med | 0.28 | 4.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244). | ||
| CVE-2018-20937 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321). | ||
| CVE-2016-10835 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107). | ||
| CVE-2018-20907 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432). | ||
| CVE-2018-20906 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430). | ||
| CVE-2018-20904 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427). | ||
| CVE-2018-20898 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396). | ||
| CVE-2018-20892 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439). | ||
| CVE-2018-20890 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426). | ||
| CVE-2019-14413 | Med | 0.28 | 4.3 | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476). | ||
| CVE-2019-14408 | Med | 0.28 | 4.3 | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460). | ||
| CVE-2019-14403 | Med | 0.28 | 4.3 | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483). | ||
| CVE-2020-29135 | Med | 0.27 | 4.1 | 0.01 | Nov 27, 2020 | cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567). | ||
| CVE-2017-18398 | Low | 0.25 | 3.8 | 0.01 | Aug 2, 2019 | DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331). | ||
| CVE-2017-18384 | Low | 0.25 | 3.8 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310). | ||
| CVE-2018-20927 | Low | 0.25 | 3.8 | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382). | ||
| CVE-2018-20896 | Low | 0.25 | 3.9 | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394). | ||
| CVE-2017-18399 | Low | 0.24 | 3.7 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332). | ||
| CVE-2017-18436 | Low | 0.23 | 3.5 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239). |
- risk 0.28cvss 4.3epss 0.01
cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).
- risk 0.28cvss 4.3epss 0.01
cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).
- risk 0.28cvss 4.3epss 0.01
cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).
- risk 0.28cvss 4.3epss 0.01
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).
- risk 0.28cvss 4.3epss 0.01
cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).
- risk 0.28cvss 4.3epss 0.01
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).
- risk 0.28cvss 4.3epss 0.01
cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427).
- risk 0.28cvss 4.3epss 0.01
cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).
- risk 0.28cvss 4.3epss 0.01
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).
- risk 0.28cvss 4.3epss 0.01
cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).
- risk 0.28cvss 4.3epss 0.01
cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).
- risk 0.28cvss 4.3epss 0.01
cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).
- risk 0.28cvss 4.3epss 0.01
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
- risk 0.27cvss 4.1epss 0.01
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
- risk 0.25cvss 3.8epss 0.01
DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).
- risk 0.25cvss 3.8epss 0.00
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
- risk 0.25cvss 3.8epss 0.00
cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).
- risk 0.25cvss 3.9epss 0.00
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
- risk 0.24cvss 3.7epss 0.01
cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332).
- risk 0.23cvss 3.5epss 0.00
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
Page 17 of 22