cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
In cPanel before 57.9999.54, /scripts/maildirconverter exposed a TTY to an unprivileged process (SEC-115).
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).
In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
cPanel before 57.9999.54 allows demo-mode escape via showtemplate.stor (SEC-119).
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajaxmaketextsyntaxutil.pl (SEC-109).
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58).
cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).
cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
cPanel before 11.54.0.4 allows SQL injection in bin/hordeupdateusernames (SEC-71).
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/checksystemstorable (SEC-78).
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magicrevision (SEC-100).
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).