Filtered by vendor Cpanel
Subscribe
Total
426 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-20905 | 1 Cpanel | 1 Cpanel | 2020-08-24 | 5.5 MEDIUM | 5.4 MEDIUM |
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429). | |||||
CVE-2018-20880 | 1 Cpanel | 1 Cpanel | 2020-08-24 | 2.1 LOW | 3.3 LOW |
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445). | |||||
CVE-2019-14401 | 1 Cpanel | 1 Cpanel | 2020-08-24 | 6.5 MEDIUM | 8.8 HIGH |
cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480). | |||||
CVE-2019-20496 | 1 Cpanel | 1 Cpanel | 2020-03-19 | 4.9 MEDIUM | 5.5 MEDIUM |
cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532). | |||||
CVE-2019-20497 | 1 Cpanel | 1 Cpanel | 2020-03-19 | 3.5 LOW | 5.4 MEDIUM |
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533). | |||||
CVE-2020-10113 | 1 Cpanel | 1 Cpanel | 2020-03-19 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515). | |||||
CVE-2020-10114 | 1 Cpanel | 1 Cpanel | 2020-03-19 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535). | |||||
CVE-2020-10118 | 1 Cpanel | 1 Cpanel | 2020-03-19 | 6.4 MEDIUM | 9.1 CRITICAL |
cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543). | |||||
CVE-2020-10121 | 1 Cpanel | 1 Cpanel | 2020-03-19 | 7.5 HIGH | 9.8 CRITICAL |
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546). | |||||
CVE-2020-10119 | 1 Cpanel | 1 Cpanel | 2020-03-19 | 7.5 HIGH | 9.8 CRITICAL |
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544). | |||||
CVE-2019-20493 | 1 Cpanel | 1 Cpanel | 2020-03-18 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520). | |||||
CVE-2012-6449 | 1 Cpanel | 2 Cpanel, Whm | 2020-02-13 | 3.5 LOW | 5.4 MEDIUM |
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability. | |||||
CVE-2012-6448 | 1 Cpanel | 1 Webhost Manager | 2020-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2017-5614 | 1 Cpanel | 1 Cpanel | 2019-10-31 | 5.8 MEDIUM | 6.1 MEDIUM |
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter. | |||||
CVE-2019-17375 | 1 Cpanel | 1 Cpanel | 2019-10-11 | 6.5 MEDIUM | 8.8 HIGH |
cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517). | |||||
CVE-2019-17378 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526). | |||||
CVE-2019-17379 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527). | |||||
CVE-2019-17377 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524). | |||||
CVE-2019-17376 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521). | |||||
CVE-2019-17380 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528). |