2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14409 | — | — | 0.4% | Jul 30, 2019 | cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466). |
| CVE-2019-14408 | — | — | 0.6% | Jul 30, 2019 | cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460). |
| CVE-2019-14407 | — | — | 0.7% | Jul 30, 2019 | cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415). |
| CVE-2019-14406 | — | — | 0.6% | Jul 30, 2019 | cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493). |
| CVE-2019-14405 | — | — | 1.5% | Jul 30, 2019 | cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487). |
| CVE-2019-14404 | — | — | 0.4% | Jul 30, 2019 | cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_s... |
| CVE-2019-14403 | — | — | 0.7% | Jul 30, 2019 | cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483). |
| CVE-2019-14402 | — | — | 0.3% | Jul 30, 2019 | cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481). |
| CVE-2019-14401 | — | — | 1.5% | Jul 30, 2019 | cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480). |
| CVE-2019-14400 | — | — | 0.4% | Jul 30, 2019 | cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479). |
| CVE-2019-14399 | — | — | 0.3% | Jul 30, 2019 | The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root ac... |
| CVE-2019-14398 | — | — | 1.5% | Jul 30, 2019 | cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498). |
| CVE-2019-14397 | — | — | 0.8% | Jul 30, 2019 | cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496). |
| CVE-2019-14396 | — | — | 0.3% | Jul 30, 2019 | API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495). |
| CVE-2019-14395 | — | — | 0.3% | Jul 30, 2019 | cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494). |
| CVE-2019-14394 | — | — | 0.2% | Jul 30, 2019 | cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for... |
| CVE-2019-14393 | — | — | 0.4% | Jul 30, 2019 | cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp ... |
| CVE-2019-14392 | — | — | 1.8% | Jul 30, 2019 | cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501). |
| CVE-2019-14391 | — | — | 0.4% | Jul 30, 2019 | cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514). |
| CVE-2019-14390 | — | — | 0.6% | Jul 30, 2019 | cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512). |
| CVE-2019-14389 | — | — | 0.4% | Jul 30, 2019 | cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510). |
| CVE-2019-14388 | — | — | 1.1% | Jul 30, 2019 | cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507). |
| CVE-2019-14387 | — | — | 0.8% | Jul 30, 2019 | cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506). |
| CVE-2019-14386 | — | — | 0.6% | Jul 30, 2019 | cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504). |
| CVE-2019-14381 | — | — | 1.4% | Jul 30, 2019 | libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now