Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2017-11441
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.…
Whm
after 56.0.50
MEDIUM 6.1
CVE-2017-5616
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum para…
Cgiecho
Mitigation only
HIGH 7.8
CVE-2017-5613
Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.
Cgiecho
Mitigation only
MEDIUM 6.1
CVE-2017-5614
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via…
Cpanel
11.54.0.36 / 56.0.43+
MEDIUM 6.1
CVE-2017-5615
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
Cgiecho
Mitigation only
MEDIUM 5.0
CVE-2008-7142
Absolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote attackers to list ar…
Cpanel
No fix yet
MEDIUM 5.0
CVE-2009-2275
Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in…
Cpanel
No fix yet
HIGH 8.5
CVE-2008-2478
scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to ex…
Cpanel
after 11.23.1
HIGH 7.8
CVE-2007-3367
Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to obtain sensitive information via a …
Cpanel
after 11.4.19
HIGH 7.5
CVE-2007-0854EPSS 6%
Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote attackers to execute arbitrary code via a URL …
Webhost Manager
No fix yet
MEDIUM 6.8
CVE-2006-6523
Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTM…
Cpanel
No fix yet
MEDIUM 6.0
CVE-2006-6198
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web sc…
Webhost Manager
No fix yet
HIGH 8.8
CVE-2006-5014
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqlad…
Cpanel
Patch available
MEDIUM 5.1
CVE-2006-2825
cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical …
Cpanel
No fix yet
MEDIUM 5.5
CVE-2004-1603
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files …
Cpanel
Patch available
MEDIUM 5.0
CVE-2004-1604
cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created wh…
Cpanel
Mitigation only
HIGH 7.2
CVE-2004-0490
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use th…
Cpanel
No fix yet
HIGH 9.3
CVE-2004-1875
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) ema…
Cpanel
Patch available
HIGH 10.0
CVE-2004-1769EPSS 35%
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to ex…
Cpanel
No fix yet
HIGH 10.0
CVE-2004-1770EPSS 10%
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user …
Cpanel
Patch available
HIGH 10.0
CVE-2003-1425EPSS 11%
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
Cpanel
No fix yet
MEDIUM 6.8
CVE-2003-0521
Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator priv…
Cpanel
Mitigation only