Cpanel
by CPanel
CVEs (413)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20870 | 0.00 | — | 0.00 | Jul 30, 2019 | The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467). | |||
| CVE-2018-20869 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465). | |||
| CVE-2018-20862 | 0.00 | — | 0.00 | Jul 30, 2019 | cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366). | |||
| CVE-2018-20868 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464). | |||
| CVE-2018-20866 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). | |||
| CVE-2018-20865 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459). | |||
| CVE-2018-20864 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). | |||
| CVE-2018-20863 | 0.00 | — | 0.02 | Jul 30, 2019 | cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452). | |||
| CVE-2019-14414 | 0.00 | — | 0.00 | Jul 30, 2019 | In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478). | |||
| CVE-2019-14413 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476). | |||
| CVE-2019-14412 | 0.00 | — | 0.00 | Jul 30, 2019 | Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474). | |||
| CVE-2019-14411 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473). | |||
| CVE-2019-14410 | 0.00 | — | 0.00 | Jul 30, 2019 | Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472). | |||
| CVE-2019-14409 | 0.00 | — | 0.00 | Jul 30, 2019 | cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466). | |||
| CVE-2019-14408 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460). | |||
| CVE-2019-14407 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415). | |||
| CVE-2019-14406 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493). | |||
| CVE-2019-14405 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487). | |||
| CVE-2019-14404 | 0.00 | — | 0.00 | Jul 30, 2019 | cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484). | |||
| CVE-2019-14403 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483). |
- CVE-2018-20870Jul 30, 2019risk 0.00cvss —epss 0.00
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
- CVE-2018-20869Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
- CVE-2018-20862Jul 30, 2019risk 0.00cvss —epss 0.00
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
- CVE-2018-20868Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
- CVE-2018-20866Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
- CVE-2018-20865Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
- CVE-2018-20864Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
- CVE-2018-20863Jul 30, 2019risk 0.00cvss —epss 0.02
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
- CVE-2019-14414Jul 30, 2019risk 0.00cvss —epss 0.00
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
- CVE-2019-14413Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).
- CVE-2019-14412Jul 30, 2019risk 0.00cvss —epss 0.00
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
- CVE-2019-14411Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).
- CVE-2019-14410Jul 30, 2019risk 0.00cvss —epss 0.00
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
- CVE-2019-14409Jul 30, 2019risk 0.00cvss —epss 0.00
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
- CVE-2019-14408Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).
- CVE-2019-14407Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
- CVE-2019-14406Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
- CVE-2019-14405Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
- CVE-2019-14404Jul 30, 2019risk 0.00cvss —epss 0.00
cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).
- CVE-2019-14403Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
Page 19 of 21