Записи cpanel
431 опубликованных записей вендора cpanel.
Профиль для исследователя
- Попали в KEV
- 1 · 0,2 %
- С эксплойтом
- 1 · 0,2 %
- Pre-auth RCE
- 13
- С записью об исправлении
- 1,6 %
- Медиана: публикация → KEV
- 1 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')96
- CWE-20 Improper Input Validation72
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor30
- CWE-284 Improper Access Control21
- CWE-287 Improper Authentication11
- CWE-732 Incorrect Permission Assignment for Critical Resource10
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
431 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
97Срочно | CVE-2026-41940Готовый эксплойт | WebPros cPanel and WHM Authentication Bypass via Login Flowcpanel · cpanel · CWE-306 | Критическая9,3 | KEV | 98,5 % | 29 апр. 2026 г. |
50В плане | CVE-2004-1769Proof of concept | The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackcpanel · cpanel | Критическая10,0 | — | 34,8 % | 11 мар. 2004 г. |
44В плане | CVE-2023-29489Proof of concept | An issue was discovered in cPanel before 11.109.9999.116.cpanel · cpanel · CWE-79 | Средняя6,1 | — | 65,5 % | 27 апр. 2023 г. |
43В плане | CVE-2003-1425Proof of concept | guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.cpanel · cpanel · CWE-20 | Критическая10,0 | — | 11,5 % | 31 дек. 2003 г. |
43В плане | CVE-2004-1770Proof of concept | The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in cpanel · cpanel | Критическая10,0 | — | 10,2 % | 11 мар. 2004 г. |
40В плане | CVE-2020-26098Эксплойта нет | cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).cpanel · cpanel | Критическая9,8 | — | 3,0 % | 25 сент. 2020 г. |
40В плане | CVE-2016-10855Эксплойта нет | cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).cpanel · cpanel · CWE-20 | Критическая9,8 | — | 2,6 % | 1 авг. 2019 г. |
40В плане | CVE-2016-10858Эксплойта нет | cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).cpanel · cpanel · CWE-20 | Критическая9,8 | — | 2,5 % | 1 авг. 2019 г. |
40В плане | CVE-2016-10824Эксплойта нет | cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).cpanel · cpanel · CWE-20 | Критическая9,8 | — | 2,5 % | 1 авг. 2019 г. |
40В плане | CVE-2020-26108Эксплойта нет | cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).cpanel · cpanel | Критическая9,8 | — | 2,5 % | 25 сент. 2020 г. |
40В плане | CVE-2018-20863Эксплойта нет | cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).cpanel · cpanel · CWE-20 | Критическая9,8 | — | 2,3 % | 30 июл. 2019 г. |
40В плане | CVE-2020-10119Эксплойта нет | cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).cpanel · cpanel | Критическая9,8 | — | 2,2 % | 17 мар. 2020 г. |
40В плане | CVE-2020-10121Эксплойта нет | cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).cpanel · cpanel | Критическая9,8 | — | 1,8 % | 17 мар. 2020 г. |
39Наблюдать | CVE-2016-10817Эксплойта нет | cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).cpanel · cpanel · CWE-89 | Критическая9,8 | — | 1,6 % | 1 авг. 2019 г. |
39Наблюдать | CVE-2020-26100Эксплойта нет | chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).cpanel · cpanel | Критическая9,8 | — | 1,6 % | 25 сент. 2020 г. |
39Наблюдать | CVE-2019-20498Эксплойта нет | cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).cpanel · cpanel | Критическая9,8 | — | 1,6 % | 17 мар. 2020 г. |
39Наблюдать | CVE-2020-26101Эксплойта нет | In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).cpanel · cpanel · CWE-287 | Критическая9,8 | — | 1,4 % | 25 сент. 2020 г. |
39Наблюдать | CVE-2020-26105Эксплойта нет | In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).cpanel · cpanel · CWE-287 | Критическая9,8 | — | 1,4 % | 25 сент. 2020 г. |
39Наблюдать | CVE-2018-20887Эксплойта нет | cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).cpanel · cpanel · CWE-89 | Критическая9,8 | — | 1,1 % | 1 авг. 2019 г. |
38Наблюдать | CVE-2004-1875Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via thcpanel · cpanel · CWE-79 | Критическая9,3 | — | 4,6 % | 30 мар. 2004 г. |
36Наблюдать | CVE-2006-5014Proof of concept | Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1cpanel · cpanel · CWE-276 | Высокая8,8 | — | 4,0 % | 26 сент. 2006 г. |
36Наблюдать | CVE-2016-10828Эксплойта нет | cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).cpanel · cpanel · CWE-22 | Высокая8,8 | — | 2,6 % | 1 авг. 2019 г. |
36Наблюдать | CVE-2016-10823Эксплойта нет | cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).cpanel · cpanel · CWE-20 | Высокая8,8 | — | 2,1 % | 1 авг. 2019 г. |
36Наблюдать | CVE-2016-10850Эксплойта нет | cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).cpanel · cpanel · CWE-20 | Высокая8,8 | — | 2,1 % | 1 авг. 2019 г. |
36Наблюдать | CVE-2016-10840Эксплойта нет | cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).cpanel · cpanel · CWE-668 | Высокая8,8 | — | 2,1 % | 1 авг. 2019 г. |
- CVE-2026-4194097Срочно
WebPros cPanel and WHM Authentication Bypass via Login Flow
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 99 %cpanel · cpanel29 апр. 2026 г.
- CVE-2004-176950В плане
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attack
КритическаяCVSS 10,0Proof of conceptEPSS 35 %cpanel · cpanel11 мар. 2004 г.
- CVE-2023-2948944В плане
An issue was discovered in cPanel before 11.109.9999.116.
СредняяCVSS 6,1Proof of conceptEPSS 66 %cpanel · cpanel27 апр. 2023 г.
- CVE-2003-142543В плане
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
КритическаяCVSS 10,0Proof of conceptEPSS 11 %cpanel · cpanel31 дек. 2003 г.
- CVE-2004-177043В плане
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in
КритическаяCVSS 10,0Proof of conceptEPSS 10 %cpanel · cpanel11 мар. 2004 г.
- CVE-2020-2609840В плане
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cpanel · cpanel25 сент. 2020 г.
- CVE-2016-1085540В плане
cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cpanel · cpanel1 авг. 2019 г.
- CVE-2016-1085840В плане
cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cpanel · cpanel1 авг. 2019 г.
- CVE-2016-1082440В плане
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cpanel · cpanel1 авг. 2019 г.
- CVE-2020-2610840В плане
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cpanel · cpanel25 сент. 2020 г.
- CVE-2018-2086340В плане
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cpanel · cpanel30 июл. 2019 г.
- CVE-2020-1011940В плане
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cpanel · cpanel17 мар. 2020 г.
- CVE-2020-1012140В плане
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cpanel · cpanel17 мар. 2020 г.
- CVE-2016-1081739Наблюдать
cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cpanel · cpanel1 авг. 2019 г.
- CVE-2020-2610039Наблюдать
chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cpanel · cpanel25 сент. 2020 г.
- CVE-2019-2049839Наблюдать
cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cpanel · cpanel17 мар. 2020 г.
- CVE-2020-2610139Наблюдать
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cpanel · cpanel25 сент. 2020 г.
- CVE-2020-2610539Наблюдать
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cpanel · cpanel25 сент. 2020 г.
- CVE-2018-2088739Наблюдать
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cpanel · cpanel1 авг. 2019 г.
- CVE-2004-187538Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via th
КритическаяCVSS 9,3Proof of conceptEPSS 5 %cpanel · cpanel30 мар. 2004 г.
- CVE-2006-501436Наблюдать
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %cpanel · cpanel26 сент. 2006 г.
- CVE-2016-1082836Наблюдать
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %cpanel · cpanel1 авг. 2019 г.
- CVE-2016-1082336Наблюдать
cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %cpanel · cpanel1 авг. 2019 г.
- CVE-2016-1085036Наблюдать
cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %cpanel · cpanel1 авг. 2019 г.
- CVE-2016-1084036Наблюдать
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %cpanel · cpanel1 авг. 2019 г.