Vulnerabilities > Directadmin

DATE CVE VULNERABILITY TITLE RISK
2019-03-07 CVE-2019-9625 Cross-Site Request Forgery (CSRF) vulnerability in Directadmin 1.55
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
network
low complexity
directadmin CWE-352
8.8
2018-01-21 CVE-2017-18045 Unspecified vulnerability in Directadmin
JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request.
network
low complexity
directadmin
critical
9.8