İçeriğe atla
Noroxi

cpanel kayıtları

cpanel üreticisine ait 431 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %0,2
Silahlaştırılmış
1 · %0,2
Pre-auth RCE
13
Düzeltme kaydı olan
%1,6
Yayından KEV’e ortanca
1 gün

Tüm kayıtlar

431 kayıt
  • WebPros cPanel and WHM Authentication Bypass via Login Flow

    KritikCVSS 9,3KEVSilahlaştırılmışEPSS %99

    cpanel · cpanel29 Nis 2026

  • CVE-2004-1769
    50Planlayın

    The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attack

    KritikCVSS 10,0Kavram kanıtıEPSS %35

    cpanel · cpanel11 Mar 2004

  • CVE-2023-29489
    44Planlayın

    An issue was discovered in cPanel before 11.109.9999.116.

    OrtaCVSS 6,1Kavram kanıtıEPSS %66

    cpanel · cpanel27 Nis 2023

  • CVE-2003-1425
    43Planlayın

    guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.

    KritikCVSS 10,0Kavram kanıtıEPSS %11

    cpanel · cpanel31 Ara 2003

  • CVE-2004-1770
    43Planlayın

    The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in

    KritikCVSS 10,0Kavram kanıtıEPSS %10

    cpanel · cpanel11 Mar 2004

  • CVE-2020-26098
    40Planlayın

    cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).

    KritikCVSS 9,8İstismar yokEPSS %3

    cpanel · cpanel25 Eyl 2020

  • CVE-2016-10855
    40Planlayın

    cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).

    KritikCVSS 9,8İstismar yokEPSS %3

    cpanel · cpanel1 Ağu 2019

  • CVE-2016-10858
    40Planlayın

    cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).

    KritikCVSS 9,8İstismar yokEPSS %3

    cpanel · cpanel1 Ağu 2019

  • CVE-2016-10824
    40Planlayın

    cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).

    KritikCVSS 9,8İstismar yokEPSS %3

    cpanel · cpanel1 Ağu 2019

  • CVE-2020-26108
    40Planlayın

    cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).

    KritikCVSS 9,8İstismar yokEPSS %2

    cpanel · cpanel25 Eyl 2020

  • CVE-2018-20863
    40Planlayın

    cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).

    KritikCVSS 9,8İstismar yokEPSS %2

    cpanel · cpanel30 Tem 2019

  • CVE-2020-10119
    40Planlayın

    cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).

    KritikCVSS 9,8İstismar yokEPSS %2

    cpanel · cpanel17 Mar 2020

  • CVE-2020-10121
    40Planlayın

    cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).

    KritikCVSS 9,8İstismar yokEPSS %2

    cpanel · cpanel17 Mar 2020

  • CVE-2016-10817
    39İzleyin

    cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).

    KritikCVSS 9,8İstismar yokEPSS %2

    cpanel · cpanel1 Ağu 2019

  • CVE-2020-26100
    39İzleyin

    chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).

    KritikCVSS 9,8İstismar yokEPSS %2

    cpanel · cpanel25 Eyl 2020

  • CVE-2019-20498
    39İzleyin

    cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).

    KritikCVSS 9,8İstismar yokEPSS %2

    cpanel · cpanel17 Mar 2020

  • CVE-2020-26101
    39İzleyin

    In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).

    KritikCVSS 9,8İstismar yokEPSS %1

    cpanel · cpanel25 Eyl 2020

  • CVE-2020-26105
    39İzleyin

    In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).

    KritikCVSS 9,8İstismar yokEPSS %1

    cpanel · cpanel25 Eyl 2020

  • CVE-2018-20887
    39İzleyin

    cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).

    KritikCVSS 9,8İstismar yokEPSS %1

    cpanel · cpanel1 Ağu 2019

  • CVE-2004-1875
    38İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via th

    KritikCVSS 9,3Kavram kanıtıEPSS %5

    cpanel · cpanel30 Mar 2004

  • CVE-2006-5014
    36İzleyin

    Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    cpanel · cpanel26 Eyl 2006

  • CVE-2016-10828
    36İzleyin

    cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).

    YüksekCVSS 8,8İstismar yokEPSS %3

    cpanel · cpanel1 Ağu 2019

  • CVE-2016-10823
    36İzleyin

    cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).

    YüksekCVSS 8,8İstismar yokEPSS %2

    cpanel · cpanel1 Ağu 2019

  • CVE-2016-10850
    36İzleyin

    cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).

    YüksekCVSS 8,8İstismar yokEPSS %2

    cpanel · cpanel1 Ağu 2019

  • CVE-2016-10840
    36İzleyin

    cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).

    YüksekCVSS 8,8İstismar yokEPSS %2

    cpanel · cpanel1 Ağu 2019