Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20909 | Hig | 0.46 | 7.1 | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338). | ||
| CVE-2019-14399 | Hig | 0.46 | 7.1 | 0.00 | Jul 30, 2019 | The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477). | ||
| CVE-2016-10798 | Med | 0.44 | 6.8 | 0.01 | Aug 7, 2019 | cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134). | ||
| CVE-2017-18452 | Med | 0.44 | 6.7 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259). | ||
| CVE-2017-18411 | Med | 0.44 | 6.8 | 0.01 | Aug 2, 2019 | The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285). | ||
| CVE-2018-20926 | Med | 0.44 | 6.7 | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380). | ||
| CVE-2018-20925 | Med | 0.44 | 6.7 | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379). | ||
| CVE-2018-20882 | Med | 0.44 | 6.8 | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447). | ||
| CVE-2020-29136 | Med | 0.42 | 6.5 | 0.01 | Nov 27, 2020 | In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575). | ||
| CVE-2020-10122 | Med | 0.42 | 6.5 | 0.01 | Mar 17, 2020 | cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547). | ||
| CVE-2019-20495 | Med | 0.42 | 6.5 | 0.01 | Mar 17, 2020 | cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531). | ||
| CVE-2016-10807 | Med | 0.42 | 6.5 | 0.01 | Aug 7, 2019 | cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112). | ||
| CVE-2016-10794 | Med | 0.42 | 6.5 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154). | ||
| CVE-2016-10786 | Med | 0.42 | 6.5 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186). | ||
| CVE-2016-10785 | Med | 0.42 | 6.5 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185). | ||
| CVE-2017-18482 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213). | ||
| CVE-2017-18480 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210). | ||
| CVE-2017-18479 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2019 | In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209). | ||
| CVE-2017-18478 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207). | ||
| CVE-2017-18477 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206). |
- risk 0.46cvss 7.1epss 0.00
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).
- risk 0.46cvss 7.1epss 0.00
The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).
- risk 0.44cvss 6.8epss 0.01
cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134).
- risk 0.44cvss 6.7epss 0.00
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
- risk 0.44cvss 6.8epss 0.01
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
- risk 0.44cvss 6.7epss 0.00
cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).
- risk 0.44cvss 6.7epss 0.00
cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).
- risk 0.44cvss 6.8epss 0.00
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
- risk 0.42cvss 6.5epss 0.01
cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).
- risk 0.42cvss 6.5epss 0.01
cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).
- risk 0.42cvss 6.5epss 0.01
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).
- risk 0.42cvss 6.5epss 0.01
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
- risk 0.42cvss 6.5epss 0.01
cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).
- risk 0.42cvss 6.5epss 0.01
cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210).
- risk 0.42cvss 6.5epss 0.00
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).
Page 7 of 22