| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| cPanel before 68.0.15 does not block a username of ssl (SEC-328). |
| cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327). |
| cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326). |
| cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325). |
| cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323). |
| cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322). |
| cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318). |
| cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315). |
| cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314). |
| cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313). |
| cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311). |
| cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310). |
| cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309). |
| cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306). |
| The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials. |
| edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name. |
| In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c. |
| In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution. |
| An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI. |
| An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala. |