Vulnerabilities > Cpanel > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-02 | CVE-2017-18386 | Injection vulnerability in Cpanel cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313). | 7.2 |
2019-08-02 | CVE-2017-18383 | Permissions, Privileges, and Access Controls vulnerability in Cpanel cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309). | 7.8 |
2019-08-01 | CVE-2016-10826 | Improper Authentication vulnerability in Cpanel cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93). | 8.8 |
2019-08-01 | CVE-2016-10820 | Improper Access Control vulnerability in Cpanel cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31). | 8.8 |
2019-08-01 | CVE-2016-10816 | Improper Input Validation vulnerability in Cpanel cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121). | 8.8 |
2019-08-01 | CVE-2016-10814 | Improper Input Validation vulnerability in Cpanel cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119). | 8.8 |
2019-08-01 | CVE-2016-10834 | Improperly Implemented Security Check for Standard vulnerability in Cpanel cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105). | 8.8 |
2019-08-01 | CVE-2016-10833 | Improper Authentication vulnerability in Cpanel cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104). | 7.5 |
2019-08-01 | CVE-2016-10831 | Improper Authentication vulnerability in Cpanel cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101). | 7.2 |
2019-08-01 | CVE-2016-10830 | Improper Access Control vulnerability in Cpanel cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100). | 8.1 |