CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-18460

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).

    Published: 2 Aug 2019
    7.8
    High

    CVE-2017-18459

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).

    Published: 2 Aug 2019
    3.3
    Low

    CVE-2017-18458

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).

    Published: 2 Aug 2019
    4.4
    Medium

    CVE-2017-18457

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218).

    Published: 2 Aug 2019
    6.1
    Medium

    CVE-2017-18456

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).

    Published: 2 Aug 2019
    2.7
    Low

    CVE-2017-18455

    Last Modified: 21 Nov 2024

    In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).

    Published: 2 Aug 2019
    5.4
    Medium

    CVE-2017-18454

    Last Modified: 21 Nov 2024

    cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).

    Published: 2 Aug 2019
    4.9
    Medium

    CVE-2017-18453

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).

    Published: 2 Aug 2019
    6.7
    Medium

    CVE-2017-18452

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).

    Published: 2 Aug 2019
    5.3
    Medium

    CVE-2017-18451

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).

    Published: 2 Aug 2019
    4.5
    Medium

    CVE-2017-18450

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).

    Published: 2 Aug 2019
    5.5
    Medium

    CVE-2017-18449

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).

    Published: 2 Aug 2019
    5.3
    Medium

    CVE-2017-18448

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).

    Published: 2 Aug 2019
    6.3
    Medium

    CVE-2017-18447

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).

    Published: 2 Aug 2019
    6.3
    Medium

    CVE-2017-18446

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).

    Published: 2 Aug 2019
    4.3
    Medium

    CVE-2017-18445

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).

    Published: 2 Aug 2019
    5.3
    Medium

    CVE-2017-18444

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).

    Published: 2 Aug 2019
    5.8
    Medium

    CVE-2017-18443

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).

    Published: 2 Aug 2019
    5.3
    Medium

    CVE-2017-18442

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).

    Published: 2 Aug 2019
    5
    Medium

    CVE-2017-18441

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).

    Published: 2 Aug 2019
    4.3
    Medium

    CVE-2017-18440

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).

    Published: 2 Aug 2019
    6.3
    Medium

    CVE-2017-18439

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).

    Published: 2 Aug 2019
    6.3
    Medium

    CVE-2017-18438

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).

    Published: 2 Aug 2019
    4.4
    Medium

    CVE-2017-18437

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).

    Published: 2 Aug 2019
    3.5
    Low

    CVE-2017-18436

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).

    Published: 2 Aug 2019
    8.8
    High

    CVE-2019-10961

    Last Modified: 21 Nov 2024

    In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.

    Published: 2 Aug 2019
    7.3
    High

    CVE-2017-18435

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).

    Published: 2 Aug 2019
    7.8
    High

    CVE-2017-18434

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).

    Published: 2 Aug 2019
    8.8
    High

    CVE-2017-18433

    Last Modified: 21 Nov 2024

    cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).

    Published: 2 Aug 2019
    7.8
    High

    CVE-2017-18432

    Last Modified: 21 Nov 2024

    In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).

    Published: 2 Aug 2019
    7.5
    High

    CVE-2017-18431

    Last Modified: 21 Nov 2024

    cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).

    Published: 2 Aug 2019
    4.7
    Medium

    CVE-2017-18430

    Last Modified: 21 Nov 2024

    In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).

    Published: 2 Aug 2019
    3.3
    Low

    CVE-2017-18429

    Last Modified: 21 Nov 2024

    In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).

    Published: 2 Aug 2019
    9.8
    Critical

    CVE-2019-9141

    Last Modified: 21 Nov 2024

    ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers to execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for remote code execution.

    Published: 2 Aug 2019
    2.5
    Low

    CVE-2017-18428

    Last Modified: 21 Nov 2024

    In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).

    Published: 2 Aug 2019
    3.3
    Low

    CVE-2017-18427

    Last Modified: 21 Nov 2024

    In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).

    Published: 2 Aug 2019
    2.7
    Low

    CVE-2017-18426

    Last Modified: 21 Nov 2024

    cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).

    Published: 2 Aug 2019
    2.5
    Low

    CVE-2017-18425

    Last Modified: 21 Nov 2024

    In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).

    Published: 2 Aug 2019
    3.3
    Low

    CVE-2017-18424

    Last Modified: 21 Nov 2024

    In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).

    Published: 2 Aug 2019
    3.3
    Low

    CVE-2017-18423

    Last Modified: 21 Nov 2024

    In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).

    Published: 2 Aug 2019
    3.3
    Low

    CVE-2017-18422

    Last Modified: 21 Nov 2024

    In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).

    Published: 2 Aug 2019
    3.3
    Low

    CVE-2017-18421

    Last Modified: 21 Nov 2024

    cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).

    Published: 2 Aug 2019
    5.4
    Medium

    CVE-2017-18420

    Last Modified: 21 Nov 2024

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).

    Published: 2 Aug 2019
    5.4
    Medium

    CVE-2017-18419

    Last Modified: 21 Nov 2024

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).

    Published: 2 Aug 2019
    5.4
    Medium

    CVE-2017-18418

    Last Modified: 21 Nov 2024

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).

    Published: 2 Aug 2019
    5.4
    Medium

    CVE-2017-18417

    Last Modified: 21 Nov 2024

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).

    Published: 2 Aug 2019
    7.5
    High

    CVE-2019-5501

    Last Modified: 21 Nov 2024

    Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthenticated remote attackers.

    Published: 2 Aug 2019
    7.5
    High

    CVE-2019-5493

    Last Modified: 21 Nov 2024

    Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information to an unauthenticated attacker. A successful attack requires that multiple non-default options be enabled.

    Published: 2 Aug 2019
    5.5
    Medium

    CVE-2019-4275

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow an unauthorized local user to create unique catalog names that could cause a denial of service. IBM X-Force ID: 160296.

    Published: 2 Aug 2019
    7.8
    High

    CVE-2018-1987

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed in plain text in the ERP trace file. IBM X-Force ID: 154280.

    Published: 2 Aug 2019