CVE-2016-10859
Last Modified: 21 Nov 2024cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
CVE-2019-13572
Last Modified: 21 Nov 2024The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
CVE-2016-10860
Last Modified: 21 Nov 2024cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
CVE-2015-9291
Last Modified: 21 Nov 2024cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
CVE-2018-20910
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).
CVE-2018-20909
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).
CVE-2018-20908
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
CVE-2018-20907
Last Modified: 21 Nov 2024cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).
CVE-2018-20906
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).
CVE-2018-20905
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
CVE-2018-20904
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427).
CVE-2018-20903
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421).
CVE-2013-7473
Last Modified: 21 Nov 2024Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
CVE-2018-20902
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
CVE-2018-20901
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).
CVE-2013-7474
Last Modified: 21 Nov 2024Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.
CVE-2019-14472
Last Modified: 21 Nov 2024Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.
CVE-2019-14471
Last Modified: 21 Nov 2024TestLink 1.9.19 has XSS via the error.php message parameter.
CVE-2018-20900
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).
CVE-2018-20899
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).
CVE-2018-20898
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).
CVE-2018-20897
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
CVE-2018-20896
Last Modified: 21 Nov 2024cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
CVE-2018-20895
Last Modified: 21 Nov 2024In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
CVE-2018-20894
Last Modified: 21 Nov 2024cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
CVE-2018-20893
Last Modified: 21 Nov 2024cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
CVE-2018-20892
Last Modified: 21 Nov 2024cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).
CVE-2018-20891
Last Modified: 21 Nov 2024cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
CVE-2018-20890
Last Modified: 21 Nov 2024cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).
CVE-2018-20889
Last Modified: 21 Nov 2024cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
CVE-2018-20888
Last Modified: 21 Nov 2024cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
CVE-2018-11892
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none
CVE-2018-20887
Last Modified: 21 Nov 2024cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
CVE-2018-20886
Last Modified: 21 Nov 2024cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
CVE-2018-20885
Last Modified: 21 Nov 2024cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
CVE-2018-20884
Last Modified: 21 Nov 2024cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
CVE-2019-14468
Last Modified: 21 Nov 2024GnuCOBOL 2.2 has a buffer overflow in cb_push_op in cobc/field.c via crafted COBOL source code.
CVE-2018-20883
Last Modified: 21 Nov 2024cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
CVE-2018-20882
Last Modified: 21 Nov 2024cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).
CVE-2018-20881
Last Modified: 21 Nov 2024cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
CVE-2018-20880
Last Modified: 21 Nov 2024cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
CVE-2018-20879
Last Modified: 21 Nov 2024cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
CVE-2018-20878
Last Modified: 21 Nov 2024cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
CVE-2018-20877
Last Modified: 21 Nov 2024cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
CVE-2018-20876
Last Modified: 21 Nov 2024cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
CVE-2018-20875
Last Modified: 21 Nov 2024cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
CVE-2018-20874
Last Modified: 21 Nov 2024cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).
CVE-2018-20873
Last Modified: 21 Nov 2024cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
CVE-2019-14338
Last Modified: 21 Nov 2024An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a post-authentication admin.cgi?action= XSS vulnerability on the management interface.
CVE-2019-14337
Last Modified: 21 Nov 2024An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the restricted command line interface, as demonstrated by the `/bin/sh -c wget` sequence.
