2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20884 | — | — | 0.5% | Aug 1, 2019 | cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367). |
| CVE-2018-20883 | — | — | 0.7% | Aug 1, 2019 | cPanel before 74.0.8 allows FTP access during account suspension (SEC-449). |
| CVE-2018-20882 | — | — | 0.4% | Aug 1, 2019 | cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password... |
| CVE-2018-20881 | — | — | 0.5% | Aug 1, 2019 | cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446). |
| CVE-2018-20880 | — | — | 0.3% | Aug 1, 2019 | cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445). |
| CVE-2018-20879 | — | — | 1.0% | Aug 1, 2019 | cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444). |
| CVE-2018-20878 | — | — | 0.5% | Aug 1, 2019 | cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441). |
| CVE-2018-20877 | — | — | 0.5% | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437). |
| CVE-2018-20876 | — | — | 0.5% | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434). |
| CVE-2018-20875 | — | — | 0.5% | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433). |
| CVE-2018-20874 | — | — | 0.5% | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428). |
| CVE-2018-20873 | — | — | 0.3% | Aug 1, 2019 | cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409). |
| CVE-2018-20872 | — | — | 0.5% | Jul 31, 2019 | DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649. |
| CVE-2018-20871 | — | — | 2.2% | Jul 30, 2019 | In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissi... |
| CVE-2018-20861 | — | — | 1.1% | Jul 30, 2019 | libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files. |
| CVE-2018-20870 | — | — | 0.4% | Jul 30, 2019 | The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467). |
| CVE-2018-20869 | — | — | 0.5% | Jul 30, 2019 | cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465). |
| CVE-2018-20868 | — | — | 0.6% | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464). |
| CVE-2018-20866 | — | — | 0.6% | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). |
| CVE-2018-20865 | — | — | 0.6% | Jul 30, 2019 | cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459). |
| CVE-2018-20864 | — | — | 0.8% | Jul 30, 2019 | cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). |
| CVE-2018-20863 | — | — | 2.3% | Jul 30, 2019 | cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452). |
| CVE-2018-20862 | — | — | 0.4% | Jul 30, 2019 | cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366). |
| CVE-2018-20867 | — | — | 0.7% | Jul 30, 2019 | cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462). |
| CVE-2018-18570 | — | — | 2.5% | Jul 29, 2019 | Planon before Live Build 41 has XSS. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now