Vendor CVEs
CPanel
All CVEs
436 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20902 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408). | |||
| CVE-2018-20901 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400). | |||
| CVE-2018-20900 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399). | |||
| CVE-2018-20899 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398). | |||
| CVE-2018-20898 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396). | |||
| CVE-2018-20897 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395). | |||
| CVE-2018-20896 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394). | |||
| CVE-2018-20895 | 0.00 | — | 0.01 | Aug 1, 2019 | In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393). | |||
| CVE-2018-20894 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443). | |||
| CVE-2018-20893 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442). | |||
| CVE-2018-20892 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439). | |||
| CVE-2018-20891 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436). | |||
| CVE-2018-20890 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426). | |||
| CVE-2018-20889 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425). | |||
| CVE-2018-20888 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424). | |||
| CVE-2018-20887 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows SQL injection during database backups (SEC-420). | |||
| CVE-2018-20886 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418). | |||
| CVE-2018-20885 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416). | |||
| CVE-2018-20884 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367). | |||
| CVE-2018-20883 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows FTP access during account suspension (SEC-449). | |||
| CVE-2018-20882 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447). | |||
| CVE-2018-20881 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446). | |||
| CVE-2018-20880 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445). | |||
| CVE-2018-20879 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444). | |||
| CVE-2018-20878 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441). | |||
| CVE-2018-20877 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437). | |||
| CVE-2018-20876 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434). | |||
| CVE-2018-20875 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433). | |||
| CVE-2018-20874 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428). | |||
| CVE-2018-20873 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409). | |||
| CVE-2018-20870 | 0.00 | — | 0.00 | Jul 30, 2019 | The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467). | |||
| CVE-2018-20869 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465). | |||
| CVE-2018-20862 | 0.00 | — | 0.00 | Jul 30, 2019 | cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366). | |||
| CVE-2018-20868 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464). | |||
| CVE-2018-20866 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). | |||
| CVE-2018-20865 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459). | |||
| CVE-2018-20864 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). | |||
| CVE-2018-20863 | 0.00 | — | 0.02 | Jul 30, 2019 | cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452). | |||
| CVE-2019-14414 | 0.00 | — | 0.00 | Jul 30, 2019 | In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478). | |||
| CVE-2019-14413 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476). | |||
| CVE-2019-14412 | 0.00 | — | 0.00 | Jul 30, 2019 | Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474). | |||
| CVE-2019-14411 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473). | |||
| CVE-2019-14410 | 0.00 | — | 0.00 | Jul 30, 2019 | Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472). | |||
| CVE-2019-14409 | 0.00 | — | 0.00 | Jul 30, 2019 | cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466). | |||
| CVE-2019-14408 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460). | |||
| CVE-2019-14407 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415). | |||
| CVE-2019-14406 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493). | |||
| CVE-2019-14405 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487). | |||
| CVE-2019-14404 | 0.00 | — | 0.00 | Jul 30, 2019 | cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484). | |||
| CVE-2019-14403 | 0.00 | — | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483). |
- CVE-2018-20902Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
- CVE-2018-20901Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).
- CVE-2018-20900Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).
- CVE-2018-20899Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).
- CVE-2018-20898Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).
- CVE-2018-20897Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
- CVE-2018-20896Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
- CVE-2018-20895Aug 1, 2019risk 0.00cvss —epss 0.01
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
- CVE-2018-20894Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
- CVE-2018-20893Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
- CVE-2018-20892Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).
- CVE-2018-20891Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
- CVE-2018-20890Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).
- CVE-2018-20889Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
- CVE-2018-20888Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
- CVE-2018-20887Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
- CVE-2018-20886Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
- CVE-2018-20885Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
- CVE-2018-20884Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
- CVE-2018-20883Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
- CVE-2018-20882Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).
- CVE-2018-20881Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
- CVE-2018-20880Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
- CVE-2018-20879Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
- CVE-2018-20878Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
- CVE-2018-20877Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
- CVE-2018-20876Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
- CVE-2018-20875Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
- CVE-2018-20874Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).
- CVE-2018-20873Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
- CVE-2018-20870Jul 30, 2019risk 0.00cvss —epss 0.00
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
- CVE-2018-20869Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
- CVE-2018-20862Jul 30, 2019risk 0.00cvss —epss 0.00
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
- CVE-2018-20868Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
- CVE-2018-20866Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
- CVE-2018-20865Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
- CVE-2018-20864Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
- CVE-2018-20863Jul 30, 2019risk 0.00cvss —epss 0.02
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
- CVE-2019-14414Jul 30, 2019risk 0.00cvss —epss 0.00
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
- CVE-2019-14413Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).
- CVE-2019-14412Jul 30, 2019risk 0.00cvss —epss 0.00
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
- CVE-2019-14411Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).
- CVE-2019-14410Jul 30, 2019risk 0.00cvss —epss 0.00
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
- CVE-2019-14409Jul 30, 2019risk 0.00cvss —epss 0.00
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
- CVE-2019-14408Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).
- CVE-2019-14407Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
- CVE-2019-14406Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
- CVE-2019-14405Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
- CVE-2019-14404Jul 30, 2019risk 0.00cvss —epss 0.00
cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).
- CVE-2019-14403Jul 30, 2019risk 0.00cvss —epss 0.01
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
Page 8 of 9