SEPTEMBER 20, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

16,104 records on file
Page 334 of 537
CVE ID Score Description
1mo ago
3.8

cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).

1mo ago
2.7

cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).

1mo ago
3.3

cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).

1mo ago
3.3

cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).

1mo ago
2.5

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352).

1mo ago
2.5

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351).

1mo ago
3.3

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).

1mo ago
3.3

cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).

1mo ago
2.7

cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).

1mo ago
3.3

cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).

1mo ago
2.7

cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).

1mo ago
3.8

cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).

1mo ago
2.8

cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).

1mo ago
3.9

cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).

1mo ago
3.3

cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).

1mo ago
2.3

cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).

1mo ago
2.7

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

1mo ago
3.3

cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).

1mo ago
3.3

cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).

1mo ago
3.3

Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied.

Exploit 1mo ago
2.3

OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

1mo ago
2.4

Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved.

1mo ago
3.3

OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used for verification in TLS. This directory is most commonly referred to as OPENSSLDIR, and is configurable with the --prefix / --openssldir configuration options. For OpenSSL versions 1.1.0 and 1.1.1, the mingw configuration targets assume that resulting programs and libraries are installed in a Unix-like environment and the default prefix for program installation as well as for OPENSSLDIR should be '/usr/local'. However, mingw programs are Windows programs, and as such, find themselves looking at sub-directories of 'C:/usr/local', which may be world writable, which enables untrusted users to modify OpenSSL's default configuration, insert CA certificates, modify (or even replace) existing engine modules, etc. For OpenSSL 1.0.2, '/usr/local/ssl' is used as default for OPENSSLDIR on all Unix and Windows targets, including Visual C builds. However, some build instructions for the diverse Windows targets on 1.0.2 encourage you to specify your own --prefix. OpenSSL versions 1.1.1, 1.1.0 and 1.0.2 are affected by this issue. Due to the limited scope of affected deployments this has been assessed as low severity and therefore we are not creating new releases at this time. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).

1mo ago
3.3

In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).

1mo ago
3.3

Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).

1mo ago
3.3

Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).

1mo ago
2.7

cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).

1mo ago
3.3

cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).

1mo ago
3.3

API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).

1mo ago
3.3

cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).