Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.3
CVE-2017-18468
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
Cpanel
56.0.46 / 58.0.45+
HIGH 7.8
CVE-2017-18460
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
Cpanel
60.0.39 / 62.0.17+
HIGH 7.8
CVE-2017-18463
cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).
Cpanel
56.0.46 / 58.0.45+
HIGH 7.8
CVE-2017-18459
cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).
Cpanel
56.0.46 / 58.0.45+
MEDIUM 6.7
CVE-2017-18452
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 6.1
CVE-2017-18456
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
Cpanel
56.0.46 / 58.0.45+
MEDIUM 5.5
CVE-2017-18449
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 5.4
CVE-2017-18454
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 5.3
CVE-2017-18448
cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 5.3
CVE-2017-18451
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 6.3
CVE-2017-18438
cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 6.3
CVE-2017-18439
cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 6.3
CVE-2017-18446
cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 6.3
CVE-2017-18447
cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 5.8
CVE-2017-18443
cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 5.3
CVE-2017-18442
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 5.3
CVE-2017-18444
cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 5.0
CVE-2017-18441
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
Cpanel
56.0.49 / 58.0.49+
HIGH 7.3
CVE-2017-18435
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
Cpanel
56.0.49 / 58.0.49+
HIGH 8.8
CVE-2017-18433
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
Cpanel
56.0.49 / 58.0.49+
HIGH 7.8
CVE-2017-18432
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
Cpanel
56.0.49 / 58.0.49+
HIGH 7.8
CVE-2017-18434
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).
Cpanel
56.0.49 / 58.0.49+
HIGH 7.5
CVE-2017-18431
cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
Cpanel
66.0.1+
MEDIUM 5.4
CVE-2017-18417
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
Cpanel
66.0.2+
MEDIUM 5.4
CVE-2017-18418
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
Cpanel
66.0.2+
MEDIUM 5.4
CVE-2017-18419
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
Cpanel
66.0.2+
MEDIUM 5.4
CVE-2017-18420
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
Cpanel
66.0.2+
HIGH 7.8
CVE-2017-18413
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
Cpanel
56.0.52 / 60.0.48+
HIGH 7.8
CVE-2017-18415
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).
Cpanel
56.0.52 / 60.0.48+
HIGH 7.5
CVE-2017-18406
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
Cpanel
64.0.40 / 66.0.23+