Vendor CVEs
CPanel
All CVEs
446 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18384 | Low | 0.25 | 3.8 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310). | ||
| CVE-2018-20927 | Low | 0.25 | 3.8 | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382). | ||
| CVE-2018-20896 | Low | 0.25 | 3.9 | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394). | ||
| CVE-2017-18399 | Low | 0.24 | 3.7 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332). | ||
| CVE-2017-18436 | Low | 0.23 | 3.5 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239). | ||
| CVE-2019-20494 | Low | 0.21 | 3.3 | 0.00 | Mar 17, 2020 | In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525). | ||
| CVE-2016-10796 | Low | 0.21 | 3.3 | 0.00 | Aug 6, 2019 | cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130). | ||
| CVE-2016-10772 | Low | 0.21 | 3.3 | 0.00 | Aug 5, 2019 | cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168). | ||
| CVE-2017-18458 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219). | ||
| CVE-2017-18429 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291). | ||
| CVE-2017-18427 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289). | ||
| CVE-2017-18424 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274). | ||
| CVE-2017-18423 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273). | ||
| CVE-2017-18422 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272). | ||
| CVE-2017-18421 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271). | ||
| CVE-2017-18397 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330). | ||
| CVE-2018-20946 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355). | ||
| CVE-2018-20944 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353). | ||
| CVE-2018-20940 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342). | ||
| CVE-2018-20939 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339). | ||
| CVE-2018-20936 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308). | ||
| CVE-2018-20894 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443). | ||
| CVE-2018-20880 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445). | ||
| CVE-2018-20873 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409). | ||
| CVE-2019-14414 | Low | 0.21 | 3.3 | 0.00 | Jul 30, 2019 | In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478). | ||
| CVE-2019-14412 | Low | 0.21 | 3.3 | 0.00 | Jul 30, 2019 | Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474). | ||
| CVE-2019-14410 | Low | 0.21 | 3.3 | 0.00 | Jul 30, 2019 | Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472). | ||
| CVE-2019-14402 | Low | 0.21 | 3.3 | 0.00 | Jul 30, 2019 | cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481). | ||
| CVE-2019-14396 | Low | 0.21 | 3.3 | 0.00 | Jul 30, 2019 | API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495). | ||
| CVE-2019-14395 | Low | 0.21 | 3.3 | 0.00 | Jul 30, 2019 | cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494). | ||
| CVE-2019-14391 | Low | 0.21 | 3.3 | 0.00 | Jul 30, 2019 | cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514). | ||
| CVE-2017-18404 | Low | 0.20 | 3.1 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341). | ||
| CVE-2017-18466 | Low | 0.18 | 2.7 | 0.01 | Aug 5, 2019 | cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228). | ||
| CVE-2017-18455 | Low | 0.18 | 2.7 | 0.01 | Aug 2, 2019 | In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208). | ||
| CVE-2017-18426 | Low | 0.18 | 2.7 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288). | ||
| CVE-2017-18401 | Low | 0.18 | 2.7 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334). | ||
| CVE-2017-18395 | Low | 0.18 | 2.7 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 does not block a username of ssl (SEC-328). | ||
| CVE-2017-18394 | Low | 0.18 | 2.7 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327). | ||
| CVE-2017-18393 | Low | 0.18 | 2.7 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326). | ||
| CVE-2017-18382 | Low | 0.18 | 2.7 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306). | ||
| CVE-2018-20938 | Low | 0.18 | 2.7 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324). | ||
| CVE-2018-20932 | Low | 0.18 | 2.7 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406). | ||
| CVE-2018-20897 | Low | 0.18 | 2.8 | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395). | ||
| CVE-2019-14407 | Low | 0.18 | 2.7 | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415). | ||
| CVE-2017-18428 | Low | 0.16 | 2.5 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290). | ||
| CVE-2017-18425 | Low | 0.16 | 2.5 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280). | ||
| CVE-2017-18412 | Low | 0.16 | 2.5 | 0.00 | Aug 2, 2019 | cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296). | ||
| CVE-2017-18391 | Low | 0.16 | 2.5 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323). | ||
| CVE-2018-20943 | Low | 0.16 | 2.5 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352). | ||
| CVE-2018-20942 | Low | 0.16 | 2.5 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351). |
- risk 0.25cvss 3.8epss 0.00
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
- risk 0.25cvss 3.8epss 0.00
cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).
- risk 0.25cvss 3.9epss 0.00
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
- risk 0.24cvss 3.7epss 0.01
cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332).
- risk 0.23cvss 3.5epss 0.00
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).
- risk 0.21cvss 3.3epss 0.00
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).
- risk 0.21cvss 3.3epss 0.00
cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168).
- risk 0.21cvss 3.3epss 0.00
cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
- risk 0.21cvss 3.3epss 0.00
cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
- risk 0.21cvss 3.3epss 0.00
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
- risk 0.21cvss 3.3epss 0.00
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
- risk 0.21cvss 3.3epss 0.00
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
- risk 0.21cvss 3.3epss 0.00
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
- risk 0.21cvss 3.3epss 0.00
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
- risk 0.21cvss 3.3epss 0.00
cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
- risk 0.21cvss 3.3epss 0.00
API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
- risk 0.21cvss 3.3epss 0.00
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
- risk 0.21cvss 3.3epss 0.00
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
- risk 0.20cvss 3.1epss 0.00
cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).
- risk 0.18cvss 2.7epss 0.01
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228).
- risk 0.18cvss 2.7epss 0.01
In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).
- risk 0.18cvss 2.7epss 0.01
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
- risk 0.18cvss 2.7epss 0.01
cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334).
- risk 0.18cvss 2.7epss 0.01
cPanel before 68.0.15 does not block a username of ssl (SEC-328).
- risk 0.18cvss 2.7epss 0.01
cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).
- risk 0.18cvss 2.7epss 0.01
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).
- risk 0.18cvss 2.7epss 0.01
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
- risk 0.18cvss 2.7epss 0.01
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).
- risk 0.18cvss 2.7epss 0.01
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
- risk 0.18cvss 2.8epss 0.00
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
- risk 0.18cvss 2.7epss 0.01
cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
- risk 0.16cvss 2.5epss 0.00
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
- risk 0.16cvss 2.5epss 0.00
In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
- risk 0.16cvss 2.5epss 0.00
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
- risk 0.16cvss 2.5epss 0.00
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323).
- risk 0.16cvss 2.5epss 0.00
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352).
- risk 0.16cvss 2.5epss 0.00
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351).
Page 8 of 9