Vulnerabilities > Cpanel > High

DATE CVE VULNERABILITY TITLE RISK
2019-07-30 CVE-2019-14401 Unspecified vulnerability in Cpanel
cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).
network
low complexity
cpanel
8.8
2019-07-30 CVE-2019-14400 Unspecified vulnerability in Cpanel
cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).
local
low complexity
cpanel
7.8
2019-07-30 CVE-2019-14399 Unspecified vulnerability in Cpanel
The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).
local
low complexity
cpanel
7.1
2019-07-30 CVE-2019-14398 Unspecified vulnerability in Cpanel
cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).
network
low complexity
cpanel
8.8
2019-07-30 CVE-2018-20869 Improper Input Validation vulnerability in Cpanel
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
local
low complexity
cpanel CWE-20
7.8
2019-07-30 CVE-2018-20862 Unspecified vulnerability in Cpanel
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
local
low complexity
cpanel
7.8
2019-07-30 CVE-2019-14392 Unspecified vulnerability in Cpanel
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
network
low complexity
cpanel
8.8
2019-07-30 CVE-2019-14389 Unspecified vulnerability in Cpanel
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
local
low complexity
cpanel
7.8
2019-07-30 CVE-2019-14388 Unspecified vulnerability in Cpanel
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
network
low complexity
cpanel
7.5
2017-03-03 CVE-2017-5613 Use of Externally-Controlled Format String vulnerability in Cpanel Cgiecho and Cgiemail
Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.
local
low complexity
cpanel CWE-134
7.8