Search Results (Refine Search)
- Results Type: Overview
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2019-14471 |
TestLink 1.9.19 has XSS via the error.php message parameter. Published: August 01, 2019; 11:15:15 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2019-14259 |
On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request. Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 8.0 HIGH V2.0: 7.7 HIGH |
CVE-2019-13572 |
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection. Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
CVE-2018-20923 |
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20922 |
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20921 |
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20920 |
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20919 |
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20918 |
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20917 |
cPanel before 70.0.23 allows any user to disable Solr (SEC-371). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 5.5 MEDIUM V2.0: 2.1 LOW |
CVE-2018-20916 |
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2018-20915 |
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2018-20914 |
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 7.3 HIGH V2.0: 4.9 MEDIUM |
CVE-2018-20913 |
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 4.9 MEDIUM V2.0: 3.5 LOW |
CVE-2018-20912 |
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 6.3 MEDIUM V2.0: 6.5 MEDIUM |
CVE-2018-20911 |
cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 7.2 HIGH V2.0: 6.5 MEDIUM |
CVE-2018-20910 |
cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20909 |
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 7.1 HIGH V2.0: 3.6 LOW |
CVE-2018-20908 |
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 5.5 MEDIUM V2.0: 2.1 LOW |
CVE-2018-20907 |
cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 4.3 MEDIUM V2.0: 4.0 MEDIUM |