Vulnerabilities > Cpanel > High

DATE CVE VULNERABILITY TITLE RISK
2019-08-01 CVE-2016-10837 Untrusted Search Path vulnerability in Cpanel
cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).
network
high complexity
cpanel CWE-426
7.5
2019-08-01 CVE-2018-20914 Injection vulnerability in Cpanel
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
network
low complexity
cpanel CWE-74
7.3
2019-08-01 CVE-2018-20911 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).
network
low complexity
cpanel CWE-79
7.2
2019-08-01 CVE-2018-20909 Incorrect Permission Assignment for Critical Resource vulnerability in Cpanel
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).
local
low complexity
cpanel CWE-732
7.1
2019-08-01 CVE-2016-10860 Improper Access Control vulnerability in Cpanel
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
network
low complexity
cpanel CWE-284
8.1
2019-08-01 CVE-2016-10859 Improper Authorization vulnerability in Cpanel
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
network
low complexity
cpanel CWE-285
8.1
2019-08-01 CVE-2016-10850 Improper Input Validation vulnerability in Cpanel
cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
network
low complexity
cpanel CWE-20
8.8
2019-08-01 CVE-2015-9291 Improper Access Control vulnerability in Cpanel
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
network
low complexity
cpanel CWE-284
7.5
2019-08-01 CVE-2018-20895 Improper Input Validation vulnerability in Cpanel
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
network
low complexity
cpanel CWE-20
7.2
2019-07-30 CVE-2019-14405 Unspecified vulnerability in Cpanel
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
network
low complexity
cpanel
8.8