Vulnerabilities (CVE)

Total 400148 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18486 1 Jitbit 1 Helpdesk 2026-06-17 6.5 MEDIUM 7.2 HIGH
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.
CVE-2017-18485 1 Elementalpath 2 Cognitoys Dino, Cognitoys Dino Firmware 2026-06-17 5.8 MEDIUM 5.4 MEDIUM
Cognitoys Dino devices allow profiles_add.html CSRF.
CVE-2017-18484 1 Elementalpath 2 Cognitoys Dino, Cognitoys Dino Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cognitoys Dino devices allow XSS via the SSID.
CVE-2017-18483 1 Annke 2 Sp1, Sp1 Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
ANNKE SP1 HD wireless camera 3.4.1.1604071109 devices allow XSS via a crafted SSID.
CVE-2017-18482 1 Cpanel 1 Cpanel 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).
CVE-2017-18481 1 Cpanel 1 Cpanel 2026-06-17 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
CVE-2017-18480 1 Cpanel 1 Cpanel 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210).
CVE-2017-18479 1 Cpanel 1 Cpanel 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).
CVE-2017-18478 1 Cpanel 1 Cpanel 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
CVE-2017-18477 1 Cpanel 1 Cpanel 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).
CVE-2017-18476 1 Cpanel 1 Cpanel 2026-06-17 5.0 MEDIUM 7.5 HIGH
Leech Protect in cPanel before 62.0.4 does not protect certain directories (SEC-205).
CVE-2017-18475 1 Cpanel 1 Cpanel 2026-06-17 6.5 MEDIUM 8.8 HIGH
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).
CVE-2017-18474 1 Cpanel 1 Cpanel 2026-06-17 6.8 MEDIUM 6.5 MEDIUM
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
CVE-2017-18473 1 Cpanel 1 Cpanel 2026-06-17 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
CVE-2017-18472 1 Cpanel 1 Cpanel 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
CVE-2017-18471 1 Cpanel 1 Cpanel 2026-06-17 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
CVE-2017-18470 1 Cpanel 1 Cpanel 2026-06-17 4.0 MEDIUM 8.8 HIGH
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
CVE-2017-18469 1 Cpanel 1 Cpanel 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).
CVE-2017-18468 1 Cpanel 1 Cpanel 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
CVE-2017-18467 1 Cpanel 1 Cpanel 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).