Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Cpanel MEDIUM 5.3
CVE-2017-18444

cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 6.3
CVE-2017-18447

cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Zoneplayer CRITICAL 9.8
CVE-2019-9141

ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers to execute arbitrary files by…

Fix: after 2018.02
Fix from $2,300 2019-08-02
Cpanel HIGH 7.5
CVE-2017-18431

cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).

Fix: 66.0.1+
Fix from $1,950 2019-08-02
Cpanel HIGH 8.8
CVE-2017-18433

cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).

Fix: 56.0.49 / 58.0.49+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18434

cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).

Fix: 56.0.49 / 58.0.49+
Fix from $1,950 2019-08-02
Cpanel MEDIUM 5.5
CVE-2017-18405

cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).

Fix: 62.0.35 / 64.0.42+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 6.5
CVE-2017-18409

In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).

Fix: 56.0.52 / 60.0.48+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 6.5
CVE-2017-18410

In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).

Fix: 56.0.52 / 60.0.48+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 6.8
CVE-2017-18411

The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).

Fix: 56.0.52 / 60.0.48+
Fix from $1,600 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18415

cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).

Fix: 56.0.52 / 60.0.48+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18388

cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).

Fix: 62.0.35 / 64.0.42+
Fix from $1,950 2019-08-02
Cpanel HIGH 8.8
CVE-2016-10814

cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).

Fix: 11.50.6.2 / 11.52.6.1+
Fix from $1,950 2019-08-01
Cpanel HIGH 8.8
CVE-2016-10816

cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).

Fix: 11.50.6.2 / 11.52.6.1+
Fix from $1,950 2019-08-01
Cpanel HIGH 8.8
CVE-2016-10823

cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).

Fix: 11.50.5.2 / 11.52.4.1+
Fix from $1,950 2019-08-01
Cpanel CRITICAL 9.8
CVE-2016-10824

cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).

Fix: 11.50.5.2 / 11.52.4.1+
Fix from $2,300 2019-08-01
Cpanel MEDIUM 6.5
CVE-2016-10842

cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).

Fix: 11.48.5.2 / 11.50.4.3+
Fix from $1,600 2019-08-01
Cpanel MEDIUM 5.5
CVE-2018-20917

cPanel before 70.0.23 allows any user to disable Solr (SEC-371).

Fix: 70.0.23+
Fix from $1,600 2019-08-01
Cpanel MEDIUM 6.3
CVE-2018-20912

cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).

Fix: 70.0.23+
Fix from $1,600 2019-08-01
Cpanel HIGH 8.8
CVE-2016-10850

cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).

Fix: 11.48.5.2 / 11.50.4.3+
Fix from $1,950 2019-08-01
Cpanel CRITICAL 9.8
CVE-2016-10855

cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).

Fix: 11.48.5.2 / 11.50.4.3+
Fix from $2,300 2019-08-01
Cpanel CRITICAL 9.8
CVE-2016-10858

cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).

Fix: 11.48.4.8 / 11.50.3.1+
Fix from $2,300 2019-08-01
Cpanel MEDIUM 5.5
CVE-2018-20891

cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).

Fix: 70.0.53 / 72.0.10+
Fix from $1,600 2019-08-01
Cpanel HIGH 7.2
CVE-2018-20895

In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).

Fix: 68.0.39 / 70.0.43+
Fix from $1,950 2019-08-01
Openstack HIGH 8.8
CVE-2018-10899

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly c…

Fix: 1.6.1+
Fix from $1,950 2019-08-01
Cpanel MEDIUM 6.5
CVE-2018-20883

cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).

Fix: 74.0.8+
Fix from $1,600 2019-08-01
Cpanel MEDIUM 6.3
CVE-2018-20879

cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).

Fix: 74.0.8+
Fix from $1,600 2019-08-01
Cpanel MEDIUM 6.8
CVE-2018-20882

cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).

Fix: 70.0.57 / 74.0.8+
Fix from $1,600 2019-08-01
Sas Drug Development HIGH 8.8
CVE-2007-6763

SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressi…

Fix: 32drg02+
Fix from $1,950 2019-07-31
Libopenmpt MEDIUM 6.5
CVE-2018-20860

libopenmpt before 0.3.13 allows a crash with malformed MED files.

Fix: 0.3.13+
Fix from $1,600 2019-07-30