CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2019-19536

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_pro.c driver, aka CID-ead16e53c2f0.

    Published: 2 Aug 2019
    6.1
    Medium

    CVE-2019-14517

    Last Modified: 21 Nov 2024

    pandao Editor.md 1.5.0 allows XSS via the Javascript: string.

    Published: 1 Aug 2019
    4.8
    Medium

    CVE-2019-5401

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (management URL, location, contact). But admin privileges are required to configure these fields thereby reducing the likelihood of exploit. HPE Aruba has provided firmware updates to resolve the vulnerability in HP 2910-48G al Switch. Please update to W.15.14.0017.

    Published: 1 Aug 2019
    7.5
    High

    CVE-2019-14513

    Last Modified: 21 Nov 2024

    Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.

    Published: 1 Aug 2019
    8
    High

    CVE-2019-14260

    Last Modified: 21 Nov 2024

    On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input validation) issue in the password change field for the Change Password interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request.

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2016-10813

    Last Modified: 21 Nov 2024

    cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).

    Published: 1 Aug 2019
    8.8
    High

    CVE-2016-10814

    Last Modified: 21 Nov 2024

    cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10815

    Last Modified: 21 Nov 2024

    cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).

    Published: 1 Aug 2019
    8.8
    High

    CVE-2016-10816

    Last Modified: 21 Nov 2024

    cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).

    Published: 1 Aug 2019
    9.8
    Critical

    CVE-2016-10817

    Last Modified: 21 Nov 2024

    cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10818

    Last Modified: 21 Nov 2024

    cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10819

    Last Modified: 21 Nov 2024

    In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).

    Published: 1 Aug 2019
    8.8
    High

    CVE-2016-10820

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10821

    Last Modified: 21 Nov 2024

    In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).

    Published: 1 Aug 2019
    8.8
    High

    CVE-2016-10826

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).

    Published: 1 Aug 2019
    7.8
    High

    CVE-2019-14497

    Last Modified: 21 Nov 2024

    ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based buffer overflow.

    Published: 1 Aug 2019
    7.8
    High

    CVE-2019-14496

    Last Modified: 21 Nov 2024

    LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflow.

    Published: 1 Aug 2019
    8.1
    High

    CVE-2019-9140

    Last Modified: 21 Nov 2024

    When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.

    Published: 1 Aug 2019
    9.8
    Critical

    CVE-2019-14495

    Last Modified: 21 Nov 2024

    webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface.

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2016-10822

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).

    Published: 1 Aug 2019
    8.8
    High

    CVE-2016-10823

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).

    Published: 1 Aug 2019
    9.8
    Critical

    CVE-2016-10824

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).

    Published: 1 Aug 2019
    8.1
    High

    CVE-2016-10825

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2016-10827

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).

    Published: 1 Aug 2019
    8.8
    High

    CVE-2016-10828

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10829

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).

    Published: 1 Aug 2019
    8.1
    High

    CVE-2016-10830

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).

    Published: 1 Aug 2019
    7.2
    High

    CVE-2016-10831

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20953

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2018-20952

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20951

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20950

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20949

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20948

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).

    Published: 1 Aug 2019
    5.5
    Medium

    CVE-2018-20947

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).

    Published: 1 Aug 2019
    3.3
    Low

    CVE-2018-20946

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).

    Published: 1 Aug 2019
    5.7
    Medium

    CVE-2018-20945

    Last Modified: 21 Nov 2024

    bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).

    Published: 1 Aug 2019
    3.3
    Low

    CVE-2018-20944

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10832

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).

    Published: 1 Aug 2019
    2.5
    Low

    CVE-2018-20943

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352).

    Published: 1 Aug 2019
    2.5
    Low

    CVE-2018-20942

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351).

    Published: 1 Aug 2019
    5.6
    Medium

    CVE-2018-20941

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).

    Published: 1 Aug 2019
    7.5
    High

    CVE-2016-10833

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).

    Published: 1 Aug 2019
    3.3
    Low

    CVE-2018-20940

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).

    Published: 1 Aug 2019
    3.3
    Low

    CVE-2018-20939

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).

    Published: 1 Aug 2019
    2.7
    Low

    CVE-2018-20938

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).

    Published: 1 Aug 2019
    8.8
    High

    CVE-2016-10834

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).

    Published: 1 Aug 2019
    4.3
    Medium

    CVE-2018-20937

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).

    Published: 1 Aug 2019
    4.3
    Medium

    CVE-2016-10835

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).

    Published: 1 Aug 2019
    3.3
    Low

    CVE-2018-20936

    Last Modified: 21 Nov 2024

    cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).

    Published: 1 Aug 2019