Vulnerabilities > Cpanel
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-01 | CVE-2016-10840 | Exposure of Resource to Wrong Sphere vulnerability in Cpanel cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72). | 8.8 |
2019-08-01 | CVE-2016-10839 | SQL Injection vulnerability in Cpanel cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71). | 8.1 |
2019-08-01 | CVE-2016-10838 | Improper Access Control vulnerability in Cpanel cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70). | 6.5 |
2019-08-01 | CVE-2016-10837 | Untrusted Search Path vulnerability in Cpanel cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46). | 7.5 |
2019-08-01 | CVE-2016-10836 | Improper Authentication vulnerability in Cpanel cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). | 6.5 |
2019-08-01 | CVE-2018-20923 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). | 6.1 |
2019-08-01 | CVE-2018-20922 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). | 6.1 |
2019-08-01 | CVE-2018-20921 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). | 6.1 |
2019-08-01 | CVE-2018-20920 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). | 6.1 |
2019-08-01 | CVE-2018-20919 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). | 6.1 |