CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2016-10859

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).

    Published: 1 Aug 2019
    9.8
    Critical

    CVE-2019-13572

    Last Modified: 21 Nov 2024

    The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.

    Published: 1 Aug 2019
    8.1
    High

    CVE-2016-10860

    Last Modified: 21 Nov 2024

    cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).

    Published: 1 Aug 2019
    7.5
    High

    CVE-2015-9291

    Last Modified: 21 Nov 2024

    cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20910

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).

    Published: 1 Aug 2019
    7.1
    High

    CVE-2018-20909

    Last Modified: 21 Nov 2024

    cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).

    Published: 1 Aug 2019
    5.5
    Medium

    CVE-2018-20908

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).

    Published: 1 Aug 2019
    4.3
    Medium

    CVE-2018-20907

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).

    Published: 1 Aug 2019
    4.3
    Medium

    CVE-2018-20906

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20905

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).

    Published: 1 Aug 2019
    4.3
    Medium

    CVE-2018-20904

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20903

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421).

    Published: 1 Aug 2019
    8.8
    High

    CVE-2013-7473

    Last Modified: 21 Nov 2024

    Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.

    Published: 1 Aug 2019
    5.5
    Medium

    CVE-2018-20902

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20901

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2013-7474

    Last Modified: 21 Nov 2024

    Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2019-14472

    Last Modified: 21 Nov 2024

    Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2019-14471

    Last Modified: 21 Nov 2024

    TestLink 1.9.19 has XSS via the error.php message parameter.

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20900

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2018-20899

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).

    Published: 1 Aug 2019
    4.3
    Medium

    CVE-2018-20898

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).

    Published: 1 Aug 2019
    2.8
    Low

    CVE-2018-20897

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).

    Published: 1 Aug 2019
    3.9
    Low

    CVE-2018-20896

    Last Modified: 21 Nov 2024

    cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).

    Published: 1 Aug 2019
    7.2
    High

    CVE-2018-20895

    Last Modified: 21 Nov 2024

    In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).

    Published: 1 Aug 2019
    3.3
    Low

    CVE-2018-20894

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).

    Published: 1 Aug 2019
    2.3
    Low

    CVE-2018-20893

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).

    Published: 1 Aug 2019
    4.3
    Medium

    CVE-2018-20892

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).

    Published: 1 Aug 2019
    5.5
    Medium

    CVE-2018-20891

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).

    Published: 1 Aug 2019
    4.3
    Medium

    CVE-2018-20890

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).

    Published: 1 Aug 2019
    4.4
    Medium

    CVE-2018-20889

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).

    Published: 1 Aug 2019
    5.5
    Medium

    CVE-2018-20888

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).

    Published: 1 Aug 2019
    —
    Unknown

    CVE-2018-11892

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 1 Aug 2019
    9.8
    Critical

    CVE-2018-20887

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).

    Published: 1 Aug 2019
    5.3
    Medium

    CVE-2018-20886

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).

    Published: 1 Aug 2019
    5.3
    Medium

    CVE-2018-20885

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20884

    Last Modified: 21 Nov 2024

    cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).

    Published: 1 Aug 2019
    7.8
    High

    CVE-2019-14468

    Last Modified: 21 Nov 2024

    GnuCOBOL 2.2 has a buffer overflow in cb_push_op in cobc/field.c via crafted COBOL source code.

    Published: 1 Aug 2019
    6.5
    Medium

    CVE-2018-20883

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).

    Published: 1 Aug 2019
    6.8
    Medium

    CVE-2018-20882

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20881

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).

    Published: 1 Aug 2019
    3.3
    Low

    CVE-2018-20880

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).

    Published: 1 Aug 2019
    6.3
    Medium

    CVE-2018-20879

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20878

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20877

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20876

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20875

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).

    Published: 1 Aug 2019
    5.4
    Medium

    CVE-2018-20874

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).

    Published: 1 Aug 2019
    3.3
    Low

    CVE-2018-20873

    Last Modified: 21 Nov 2024

    cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).

    Published: 1 Aug 2019
    6.1
    Medium

    CVE-2019-14338

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a post-authentication admin.cgi?action= XSS vulnerability on the management interface.

    Published: 1 Aug 2019
    5.5
    Medium

    CVE-2019-14337

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the restricted command line interface, as demonstrated by the `/bin/sh -c wget` sequence.

    Published: 1 Aug 2019