CVE-2021-38589
- EPSS 0.86%
- Veröffentlicht 11.08.2021 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:17:35
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
CVE-2021-38590
- EPSS 0.26%
- Veröffentlicht 11.08.2021 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:17:35
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
CVE-2021-31803
- EPSS 0.58%
- Veröffentlicht 26.04.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:15
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
CVE-2021-26266
- EPSS 0.92%
- Veröffentlicht 26.01.2021 18:16:25
- Zuletzt bearbeitet 21.11.2024 05:56:00
cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).
CVE-2021-26267
- EPSS 0.92%
- Veröffentlicht 26.01.2021 18:16:25
- Zuletzt bearbeitet 21.11.2024 05:56:00
cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).
CVE-2020-29136
- EPSS 1.18%
- Veröffentlicht 27.11.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:40
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
CVE-2020-29137
- EPSS 0.63%
- Veröffentlicht 27.11.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:40
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
CVE-2020-29135
- EPSS 0.57%
- Veröffentlicht 27.11.2020 02:15:10
- Zuletzt bearbeitet 21.11.2024 05:23:40
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
CVE-2020-26103
- EPSS 1.31%
- Veröffentlicht 25.09.2020 06:15:14
- Zuletzt bearbeitet 21.11.2024 05:19:14
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
CVE-2020-26104
- EPSS 1.39%
- Veröffentlicht 25.09.2020 06:15:14
- Zuletzt bearbeitet 21.11.2024 05:19:14
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).