Vulnerabilities > Cpanel > Low

DATE CVE VULNERABILITY TITLE RISK
2019-08-01 CVE-2018-20884 Cross-site Scripting vulnerability in Cpanel
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
network
cpanel CWE-79
3.5
2019-07-30 CVE-2018-20862 Unspecified vulnerability in Cpanel
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
local
low complexity
cpanel
2.1
2019-07-30 CVE-2018-20870 Information Exposure vulnerability in Cpanel
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
local
low complexity
cpanel CWE-200
2.1
2019-07-30 CVE-2019-14394 Information Exposure vulnerability in Cpanel
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).
local
low complexity
cpanel CWE-200
2.1
2019-07-30 CVE-2019-14395 Information Exposure vulnerability in Cpanel
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
local
low complexity
cpanel CWE-200
2.1
2019-07-30 CVE-2019-14396 Unspecified vulnerability in Cpanel
API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
local
low complexity
cpanel
2.1
2019-07-30 CVE-2019-14402 Unspecified vulnerability in Cpanel
cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
local
low complexity
cpanel
2.1
2019-07-30 CVE-2019-14409 Information Exposure vulnerability in Cpanel
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
local
low complexity
cpanel CWE-200
2.1
2019-07-30 CVE-2019-14410 Use of Externally-Controlled Format String vulnerability in Cpanel
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
local
low complexity
cpanel CWE-134
2.1
2019-07-30 CVE-2019-14412 Use of Externally-Controlled Format String vulnerability in Cpanel
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
local
low complexity
cpanel CWE-134
2.1