Vulnerabilities > Cpanel > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-01 | CVE-2016-10841 | Information Management Errors vulnerability in Cpanel The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73). | 5.3 |
2019-08-01 | CVE-2016-10838 | Improper Access Control vulnerability in Cpanel cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70). | 6.5 |
2019-08-01 | CVE-2016-10836 | Improper Authentication vulnerability in Cpanel cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). | 6.5 |
2019-08-01 | CVE-2018-20923 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). | 6.1 |
2019-08-01 | CVE-2018-20922 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). | 6.1 |
2019-08-01 | CVE-2018-20921 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). | 6.1 |
2019-08-01 | CVE-2018-20920 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). | 6.1 |
2019-08-01 | CVE-2018-20919 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). | 6.1 |
2019-08-01 | CVE-2018-20918 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). | 6.1 |
2019-08-01 | CVE-2018-20917 | Improper Input Validation vulnerability in Cpanel cPanel before 70.0.23 allows any user to disable Solr (SEC-371). | 5.5 |