Vulnerabilities > Cpanel > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-01 | CVE-2016-10837 | Untrusted Search Path vulnerability in Cpanel cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46). | 7.5 |
2019-08-01 | CVE-2018-20914 | Injection vulnerability in Cpanel In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). | 7.3 |
2019-08-01 | CVE-2018-20911 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359). | 7.2 |
2019-08-01 | CVE-2018-20909 | Incorrect Permission Assignment for Critical Resource vulnerability in Cpanel cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338). | 7.1 |
2019-08-01 | CVE-2016-10860 | Improper Access Control vulnerability in Cpanel cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66). | 8.1 |
2019-08-01 | CVE-2016-10859 | Improper Authorization vulnerability in Cpanel cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65). | 8.1 |
2019-08-01 | CVE-2016-10850 | Improper Input Validation vulnerability in Cpanel cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83). | 8.8 |
2019-08-01 | CVE-2015-9291 | Improper Access Control vulnerability in Cpanel cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221). | 7.5 |
2019-08-01 | CVE-2018-20895 | Improper Input Validation vulnerability in Cpanel In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393). | 7.2 |
2019-07-30 | CVE-2019-14405 | Unspecified vulnerability in Cpanel cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487). | 8.8 |