CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2016-10836

    Last Modified: 21 Nov 2024

    cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20935

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2018-20934

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20933

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).

    Published: 1 Aug 2019
    2.7
    Low

    CVE-2018-20932

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).

    Published: 1 Aug 2019
    6.3
    Medium

    CVE-2018-20931

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2018-20930

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).

    Published: 1 Aug 2019
    7.5
    High

    CVE-2016-10837

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10838

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20928

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391).

    Published: 1 Aug 2019
    8.1
    High

    CVE-2016-10839

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71).

    Published: 1 Aug 2019
    8.8
    High

    CVE-2016-10840

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).

    Published: 1 Aug 2019
    5.3
    Medium

    CVE-2016-10841

    Last Modified: 21 Nov 2024

    The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10842

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).

    Published: 1 Aug 2019
    8.1
    High

    CVE-2016-10843

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10844

    Last Modified: 21 Nov 2024

    The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).

    Published: 1 Aug 2019
    8.1
    High

    CVE-2016-10845

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).

    Published: 1 Aug 2019
    8.1
    High

    CVE-2016-10846

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).

    Published: 1 Aug 2019
    8.1
    High

    CVE-2016-10847

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).

    Published: 1 Aug 2019
    7.2
    High

    CVE-2016-10848

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10849

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).

    Published: 1 Aug 2019
    7.8
    High

    CVE-2019-14486

    Last Modified: 21 Nov 2024

    GnuCOBOL 2.2 has a buffer overflow in cb_evaluate_expr in cobc/field.c via crafted COBOL source code.

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20929

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).

    Published: 1 Aug 2019
    3.8
    Low

    CVE-2018-20927

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).

    Published: 1 Aug 2019
    6.7
    Medium

    CVE-2018-20926

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).

    Published: 1 Aug 2019
    6.7
    Medium

    CVE-2018-20925

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).

    Published: 1 Aug 2019
    5.5
    Medium

    CVE-2018-20924

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).

    Published: 1 Aug 2019
    8.8
    High

    CVE-2016-10850

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20923

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20922

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20921

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20920

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20919

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2016-10851

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20918

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10852

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).

    Published: 1 Aug 2019
    5.5
    Medium

    CVE-2018-20917

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows any user to disable Solr (SEC-371).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20916

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20915

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2016-10853

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).

    Published: 1 Aug 2019
    7.3
    High

    CVE-2018-20914

    Last Modified: 21 Nov 2024

    In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).

    Published: 1 Aug 2019
    8
    High

    CVE-2019-14259

    Last Modified: 21 Nov 2024

    On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request.

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2016-10854

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).

    Published: 1 Aug 2019
    4.9
    Medium

    CVE-2018-20913

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).

    Published: 1 Aug 2019
    6.3
    Medium

    CVE-2018-20912

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).

    Published: 1 Aug 2019
    9.8
    Critical

    CVE-2016-10855

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).

    Published: 1 Aug 2019
    7.2
    High

    CVE-2018-20911

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10856

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2016-10857

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).

    Published: 1 Aug 2019
    9.8
    Critical

    CVE-2016-10858

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).

    Published: 1 Aug 2019