Search Results (91400 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2017-18471 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
CVE-2017-18456 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
CVE-2017-18454 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
CVE-2017-18446 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).
CVE-2017-18442 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
CVE-2017-18437 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
CVE-2017-18420 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
CVE-2017-18419 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
CVE-2017-18418 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
CVE-2017-18417 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
CVE-2017-18408 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
CVE-2017-18402 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).
CVE-2017-18400 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).
CVE-2017-18389 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
CVE-2017-18387 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
CVE-2017-18386 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
CVE-2017-18379 1 Linux 1 Linux Kernel 2024-11-21 9.8 Critical
In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c.
CVE-2017-18378 1 Netgear 2 Readynas Surveillance, Readynas Surveillance Firmware 2024-11-21 N/A
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.
CVE-2017-18377 1 Goahead 2 Wireless Ip Camera Wificam, Wireless Ip Camera Wificam Firmware 2024-11-21 9.8 Critical
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI.
CVE-2017-18374 2 Billion, Zyxel 6 5200w-t, 5200w-t Firmware, P660hn-t1a V1 and 3 more 2024-11-21 N/A
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true. These accounts can be used to login to the web interface, exploit authenticated command injections and change router settings for malicious purposes.