Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20494 | Low | 0.21 | 3.3 | 0.00 | Mar 17, 2020 | In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525). | ||
| CVE-2016-10796 | Low | 0.21 | 3.3 | 0.00 | Aug 6, 2019 | cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130). | ||
| CVE-2016-10772 | Low | 0.21 | 3.3 | 0.00 | Aug 5, 2019 | cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168). | ||
| CVE-2017-18458 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219). | ||
| CVE-2017-18429 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291). | ||
| CVE-2017-18427 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289). | ||
| CVE-2017-18424 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274). | ||
| CVE-2017-18423 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273). | ||
| CVE-2017-18422 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272). | ||
| CVE-2017-18421 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271). | ||
| CVE-2017-18397 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330). | ||
| CVE-2018-20946 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355). | ||
| CVE-2018-20944 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353). | ||
| CVE-2018-20940 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342). | ||
| CVE-2018-20939 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339). | ||
| CVE-2018-20936 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308). | ||
| CVE-2018-20894 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443). | ||
| CVE-2018-20880 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445). | ||
| CVE-2018-20873 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409). | ||
| CVE-2019-14414 | Low | 0.21 | 3.3 | 0.00 | Jul 30, 2019 | In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478). |
- risk 0.21cvss 3.3epss 0.00
In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).
- risk 0.21cvss 3.3epss 0.00
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).
- risk 0.21cvss 3.3epss 0.00
cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168).
- risk 0.21cvss 3.3epss 0.00
cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
- risk 0.21cvss 3.3epss 0.00
cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
- risk 0.21cvss 3.3epss 0.00
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
- risk 0.21cvss 3.3epss 0.00
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
- risk 0.21cvss 3.3epss 0.00
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
Page 18 of 22