cpanel

426 tracked vulnerabilities.

CVE-2018-20893 LOW
cPanel < 70.0.53 - Unauthenticated File Rename during Account Rename
Aug 01, 2019
CVSS 2.3
EPSS 0.00
CVE-2018-20892 MEDIUM
cPanel 69.9999.122-70.0.53 - Arbitrary Zone File Modification via CAA Record Handling
Aug 01, 2019
CVSS 4.3
EPSS 0.00
CVE-2018-20891 MEDIUM
cPanel 69.9999.122-70.0.53 - Arbitrary File Read during File Restoration
Aug 01, 2019
CVSS 5.5
EPSS 0.00
CVE-2018-20890 MEDIUM
cPanel 69.9999.122-70.0.53 - Improper Access Control in Zone File Modification
Aug 01, 2019
CVSS 4.3
EPSS 0.00
CVE-2018-20889 MEDIUM
cPanel 69.9999.122-70.0.53 - Exposure of Sensitive Information via Password File Caching
Aug 01, 2019
CVSS 4.4
EPSS 0.00
CVE-2018-20888 MEDIUM
cPanel 69.9999.122-70.0.53 - Improper Authentication
Aug 01, 2019
CVSS 5.5
EPSS 0.00
CVE-2018-20887 CRITICAL
cPanel < 74.0.0 - SQL Injection during Database Backups
Aug 01, 2019
CVSS 9.8
EPSS 0.00
CVE-2018-20886 MEDIUM
cPanel < 70.0.53 - Insecure Storage of Sensitive Information in phpMyAdmin Session Files
Aug 01, 2019
CVSS 5.3
EPSS 0.00
CVE-2018-20885 MEDIUM
cPanel < 74.0.0 - Apache HTTP Server Configuration Injection via DocumentRoot Variable Interpolation
Aug 01, 2019
CVSS 5.3
EPSS 0.00
CVE-2018-20884 MEDIUM
cPanel < 74.0.0 - Stored Cross-Site Scripting in WHM File Restoration Interface
Aug 01, 2019
CVSS 5.4
EPSS 0.00
CVE-2018-20883 MEDIUM
cPanel < 74.0.8 - Unauthenticated FTP Access During Account Suspension
Aug 01, 2019
CVSS 6.5
EPSS 0.00
CVE-2018-20882 MEDIUM
cPanel 69.9999.122-70.0.57 - Arbitrary File Write via WHM Force Password Change
Aug 01, 2019
CVSS 6.8
EPSS 0.00
CVE-2018-20881 MEDIUM
cPanel < 74.0.8 - Stored Cross-Site Scripting in Security Questions Login Page
Aug 01, 2019
CVSS 5.4
EPSS 0.00
CVE-2018-20880 LOW
cPanel < 74.0.8 - Account Suspension Bypass via Invalid email_accounts.json File
Aug 01, 2019
CVSS 3.3
EPSS 0.00
CVE-2018-20879 MEDIUM
cPanel < 74.0.8 - Authenticated Remote Code Execution via Fileman::viewfile API
Aug 01, 2019
CVSS 6.3
EPSS 0.01
CVE-2018-20878 MEDIUM
cPanel < 74.0.8 - Stored Cross-Site Scripting in WHM File and Directory Restoration Interface
Aug 01, 2019
CVSS 5.4
EPSS 0.00
CVE-2018-20877 MEDIUM
cPanel < 74.0.8 - Stored Cross-Site Scripting in WHM Style Upload Interface
Aug 01, 2019
CVSS 5.4
EPSS 0.00
CVE-2018-20876 MEDIUM
cPanel < 74.0.8 - Stored Cross-Site Scripting in Site Software Moderation Interface
Aug 01, 2019
CVSS 5.4
EPSS 0.00
CVE-2018-20875 MEDIUM
cPanel < 74.0.8 - Stored Cross-Site Scripting in WHM Security Questions Interface
Aug 01, 2019
CVSS 5.4
EPSS 0.00
CVE-2018-20874 MEDIUM
cPanel 69.9999.122-70.0.57 - Stored Cross-Site Scripting in WHM Create Account Interface
Aug 01, 2019
CVSS 5.4
EPSS 0.00
CVE-2018-20873 LOW
cPanel 69.9999.122-70.0.57 - Local ClamAV Daemon Disabling via Improper Input Validation
Aug 01, 2019
CVSS 3.3
EPSS 0.00
CVE-2018-20870 MEDIUM
cPanel < 76.0.8 - Exposure of Sensitive Information via WebDAV Debug Logging
Jul 30, 2019
CVSS 5.5
EPSS 0.00
CVE-2018-20869 HIGH
cPanel < 76.0.8 - Remote Code Execution via DNSSEC Adminbin
Jul 30, 2019
CVSS 7.8
EPSS 0.00
CVE-2018-20868 MEDIUM
cPanel < 76.0.8 - Stored Cross-Site Scripting in WHM MultiPHP Manager Interface
Jul 30, 2019
CVSS 6.1
EPSS 0.00
CVE-2018-20866 MEDIUM
cPanel < 76.0.8 - Stored Cross-Site Scripting in WHM DNS Zone Reset Feature
Jul 30, 2019
CVSS 6.1
EPSS 0.00