cpanel

426 tracked vulnerabilities.

CVE-2017-18413 HIGH
cPanel < 56.0.52 - Arbitrary File Overwrite via Backup System
Aug 02, 2019
CVSS 7.8
EPSS 0.00
CVE-2017-18412 LOW
cPanel < 56.0.52 - Sensitive Information Exposure via Apache Log File Permissions
Aug 02, 2019
CVSS 2.5
EPSS 0.00
CVE-2017-18411 MEDIUM
cPanel 55.9999.61-56.0.52 - Unauthenticated MySQL Database Exposure via Addon Domain Conversion
Aug 02, 2019
CVSS 6.8
EPSS 0.00
CVE-2017-18410 MEDIUM
cPanel < 56.0.52 - Unauthenticated MySQL Database Exposure via Backup Archive
Aug 02, 2019
CVSS 6.5
EPSS 0.00
CVE-2017-18409 MEDIUM
cPanel < 56.0.52 - Unauthenticated MySQL Database Exposure via Backup Interface
Aug 02, 2019
CVSS 6.5
EPSS 0.00
CVE-2017-18408 MEDIUM
cPanel 55.9999.61-56.0.52 - Stored Cross-Site Scripting in WHM MySQL Password Change Interface
Aug 02, 2019
CVSS 5.4
EPSS 0.00
CVE-2017-18407 MEDIUM
cPanel < 60.0.48 - Improper Verification of Cryptographic Signature for Support-Agreement Download
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2017-18406 HIGH
cPanel < 64.0.40 - SQL Injection via Eximstats Processing
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2017-18405 MEDIUM
cPanel 61.9999.55-62.0.35 - Arbitrary File Read via Backup .htaccess Modification
Aug 02, 2019
CVSS 5.5
EPSS 0.00
CVE-2017-18404 LOW
cPanel < 62.0.35 - Unauthenticated Domain Data Deletion via .lock TLD
Aug 02, 2019
CVSS 3.1
EPSS 0.00
CVE-2017-18403 MEDIUM
cPanel 61.9999.55-61.9999.9999 - Remote Code Execution via Mailman Archives
Aug 02, 2019
CVSS 6.3
EPSS 0.00
CVE-2017-18402 MEDIUM
cPanel 61.9999.55-62.0.35 - Stored Cross-Site Scripting during cpaddons Moderated Upgrade
Aug 02, 2019
CVSS 5.4
EPSS 0.00
CVE-2017-18401 LOW
cPanel 61.9999.55-62.0.35 - Improper Input Validation in Username Creation
Aug 02, 2019
CVSS 2.7
EPSS 0.00
CVE-2017-18400 HIGH
cPanel < 62.0.35 - Local Root Code Execution via cpdavd
Aug 02, 2019
CVSS 7.8
EPSS 0.00
CVE-2017-18399 LOW
cPanel < 62.0.35 - Unauthenticated Root Crontab File Read via sqloptimizer Toggle
Aug 02, 2019
CVSS 3.7
EPSS 0.00
CVE-2017-18398 LOW
cPanel 61.9999.55-61.9999.9999 - Unauthenticated Zone Creation via DnsUtils
Aug 02, 2019
CVSS 3.8
EPSS 0.00
CVE-2017-18397 LOW
cPanel <68.0.15 - Privilege Escalation
Aug 02, 2019
CVSS 3.3
EPSS 0.00
CVE-2017-18396 MEDIUM
cPanel 61.9999.55-61.9999.9999 - Unauthenticated Arbitrary File Read via Exim vdomainaliases
Aug 02, 2019
CVSS 5.5
EPSS 0.00
CVE-2017-18395 LOW
cPanel < 62.0.35 - Improper Input Validation
Aug 02, 2019
CVSS 2.7
EPSS 0.00
CVE-2017-18394 LOW
cPanel < 62.0.35 - Improper Input Validation
Aug 02, 2019
CVSS 2.7
EPSS 0.00
CVE-2017-18393 LOW
cPanel < 62.0.35 - Unauthenticated Private Email Reception via Postmaster Username
Aug 02, 2019
CVSS 2.7
EPSS 0.00
CVE-2017-18392 LOW
cPanel 63.9999.74-64.0.41 - PostgreSQL Database Assignment Collision
Aug 02, 2019
CVSS 2.0
EPSS 0.00
CVE-2017-18391 LOW
cPanel < 62.0.35 - Exposure of Sensitive Backup Files
Aug 02, 2019
CVSS 2.5
EPSS 0.00
CVE-2017-18390 HIGH
cPanel < 62.0.35 - Remote Code Execution via Incremental Backup Permissions
Aug 02, 2019
CVSS 7.8
EPSS 0.00
CVE-2017-18389 MEDIUM
cPanel < 64.0.42 - String Format Injection in dovecot-xaps-plugin
Aug 02, 2019
CVSS 6.3
EPSS 0.00