CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 21d ago | 3.5 | cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239). |
| 21d ago | 3.3 | In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291). |
| 21d ago | 2.5 | In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290). |
| 21d ago | 3.3 | In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289). |
| 21d ago | 2.7 | cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288). |
| 21d ago | 2.5 | In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280). |
| 21d ago | 3.3 | In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274). |
| 21d ago | 3.3 | In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273). |
| 21d ago | 3.3 | In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272). |
| 21d ago | 3.3 | cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271). |
| 21d ago | 2.5 | cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296). |
| 21d ago | 3.1 | cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341). |
| 21d ago | 2.7 | cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334). |
| 21d ago | 3.7 | cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332). |
| 21d ago | 3.8 | DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331). |
| 21d ago | 3.3 | cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330). |
| 21d ago | 2.7 | cPanel before 68.0.15 does not block a username of ssl (SEC-328). |
| 21d ago | 2.7 | cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327). |
| 21d ago | 2.7 | cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326). |
| 21d ago | 2 | cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325). |
| 21d ago | 2.5 | cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323). |
| 21d ago | 3.8 | cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310). |
| 21d ago | 2.7 | cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306). |
| 21d ago | 3.3 | cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355). |
| 21d ago | 3.3 | cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353). |
| 21d ago | 2.5 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352). |
| 21d ago | 2.5 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351). |
| 21d ago | 3.3 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342). |
| 21d ago | 3.3 | cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339). |
| 21d ago | 2.7 | cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324). |