CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-65643 HIGH

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

CVSS 8.7 EPSS 0.88% Sep 1, 2026
CVE-2026-29205 HIGH

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

CVSS 8.6 EPSS 0.38% May 13, 2026
CVE-2026-32992 HIGH

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

CVSS 8.2 EPSS 0.32% May 13, 2026
CVE-2026-41940 KEV CRITICAL

WebPros cPanel and WHM Authentication Bypass via Login Flow

CVSS 9.3 EPSS 98.53% Apr 29, 2026
CVE-2025-66429 HIGH

An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. T…

CVSS 8.8 EPSS 0.83% Dec 11, 2025
CVE-2022-48623 CRITICAL

The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a den…

CVSS 9.1 EPSS 0.79% Feb 13, 2024
CVE-2023-29489 MEDIUM

An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are…

CVSS 6.1 EPSS 65.53% Apr 27, 2023
CVE-2021-38584 HIGH

The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).

CVSS 7.2 EPSS 0.86% Aug 11, 2021
CVE-2021-38585 HIGH

The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).

CVSS 7.2 EPSS 1.03% Aug 11, 2021
CVE-2021-38586 MEDIUM

In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).

CVSS 4.4 EPSS 0.25% Aug 11, 2021
CVE-2021-38587 HIGH

In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).

CVSS 7.5 EPSS 0.64% Aug 11, 2021
CVE-2021-38588 HIGH

In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).

CVSS 8.1 EPSS 0.44% Aug 11, 2021
CVE-2021-38589 HIGH

In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).

CVSS 8.1 EPSS 0.85% Aug 11, 2021
CVE-2021-38590 MEDIUM

In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).

CVSS 5.5 EPSS 0.26% Aug 11, 2021
CVE-2021-31803 MEDIUM

cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).

CVSS 6.1 EPSS 0.58% Apr 26, 2021
CVE-2021-26266 HIGH

cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).

CVSS 7.5 EPSS 0.92% Jan 26, 2021
CVE-2021-26267 HIGH

cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).

CVSS 7.5 EPSS 0.92% Jan 26, 2021
CVE-2020-29136 MEDIUM

In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).

CVSS 6.5 EPSS 1.19% Nov 27, 2020
CVE-2020-29137 MEDIUM

cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).

CVSS 6.1 EPSS 0.64% Nov 27, 2020
CVE-2020-29135 MEDIUM

cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).

CVSS 4.1 EPSS 0.58% Nov 27, 2020
CVE-2020-26098 CRITICAL

cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).

CVSS 9.8 EPSS 3.00% Sep 25, 2020
CVE-2020-26099 HIGH

cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).

CVSS 7.5 EPSS 1.21% Sep 25, 2020
CVE-2020-26100 CRITICAL

chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).

CVSS 9.8 EPSS 1.61% Sep 25, 2020
CVE-2020-26101 CRITICAL

In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).

CVSS 9.8 EPSS 1.42% Sep 25, 2020
CVE-2020-26102 HIGH

In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).

CVSS 7.5 EPSS 1.39% Sep 25, 2020

Showing 1 to 25 CVEs · page 1 (more available)