<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – CentOS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/centos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/centos-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – CentOS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:03 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-48703 – CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48703</guid>
    <pubDate>Fri, 19 Sep 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-48703</strong></p>
  <p>CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-3498 – An unauthenticated user with management network access can get and 
modify the R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3498</guid>
    <pubDate>Wed, 09 Jul 2025 09:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-3498</strong></p>
  <p>An unauthenticated user with management network access can get and  modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20)  configuration. The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). An attacker can use these APIs to get access to all system settings, modify the configuration and execute some commands (e.g., sy…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3497 – The Linux distribution underlying the Radiflow iSAP Smart Collector 
(CentOS 7 -...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3497</guid>
    <pubDate>Wed, 09 Jul 2025 09:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3497</strong></p>
  <p>The Linux distribution underlying the Radiflow iSAP Smart Collector  (CentOS 7 - VSAP 1.20) is obsolete and  reached end of life (EOL) on June 30, 2024.  Thus, any  unmitigated vulnerability could be exploited to affect this product.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-1104</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44877 – login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44877</guid>
    <pubDate>Thu, 05 Jan 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44877</strong></p>
  <p>login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45467 – In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45467</guid>
    <pubDate>Mon, 26 Dec 2022 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45467</strong></p>
  <p>In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45466 – In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45466</guid>
    <pubDate>Mon, 26 Dec 2022 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45466</strong></p>
  <p>In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-41352 – An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41352</guid>
    <pubDate>Mon, 26 Sep 2022 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-41352</strong></p>
  <p>An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red H…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43816 – containerd is an open source container runtime. On installations using SELinux, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43816</guid>
    <pubDate>Wed, 05 Jan 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43816</strong></p>
  <p>containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved b…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34424 – A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34424</guid>
    <pubDate>Wed, 24 Nov 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34424</strong></p>
  <p>A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-34423 – A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34423</guid>
    <pubDate>Wed, 24 Nov 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-34423</strong></p>
  <p>A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41034 – The build of some language stacks of Eclipse Che version 6 includes pulling some...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41034</guid>
    <pubDate>Wed, 29 Sep 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41034</strong></p>
  <p>The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with arbitrary ones. The stacks involved are Java 8 (alpine and centos), Android and PHP. The vulnerability is not exploitable at runtime but only whe…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-924</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-31324 – The unprivileged user portal part of CentOS Web Panel is affected by a Command I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31324</guid>
    <pubDate>Tue, 18 May 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-31324</strong></p>
  <p>The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-31316 – The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31316</guid>
    <pubDate>Tue, 18 May 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-31316</strong></p>
  <p>The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15628 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15628</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15628</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mail_autoreply.php. When parsing the user parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. A…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15627 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15627</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15627</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mail_autoreply.php. When parsing the account parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15626 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15626</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15626</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the term parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An att…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15625 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15625</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15625</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_add_mailbox.php. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15624 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15624</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15624</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_new_account.php. When parsing the domain parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15623 – This vulnerability allows remote attackers to write arbitrary files on affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15623</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15623</strong></p>
  <p>This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the archivo parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15622 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15622</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15622</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mail_autoreply.php. When parsing the search parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15621 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15621</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15621</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mail_autoreply.php. When parsing the email parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15620 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15620</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15620</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the id parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15619 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15619</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15619</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the type parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15618 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15618</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15618</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15617 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15617</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15617</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the status parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15616 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15616</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15616</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the package parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15615 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15615</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15615</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_ftp_manager.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage thi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15614 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15614</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15614</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the cha parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15613 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15613</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15613</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_admin_apis.php. When parsing the line parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker c…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15612 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15612</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15612</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_ftp_manager.php. When parsing the userLogin parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An atta…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15611 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15611</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15611</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_restart parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15610 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15610</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15610</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the modulo parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker c…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15609 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15609</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15609</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_stop parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An att…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15608 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15608</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15608</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the ai_service parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15607 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15607</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15607</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_admin_apis.php. When parsing the line parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker c…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15606 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15606</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15606</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_admin_apis.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15435 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15435</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15435</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_start parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An at…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15434 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15434</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15434</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the canal parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker ca…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15433 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15433</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15433</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the phpversion parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attack…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15432 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15432</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15432</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_migration_cpanel.php. When parsing the filespace parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15431 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15431</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15431</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_crons.php. When parsing the user parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can le…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15430 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15430</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15430</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An att…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15429 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15429</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15429</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_crons.php. When parsing the user parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can le…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15428 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15428</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15428</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_crons.php. When parsing the line parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can le…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15427 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15427</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15427</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_disk_usage.php. When parsing the folderName parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An atta…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15426 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15426</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15426</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_migration_cpanel.php. When parsing the serverip parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15425 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15425</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15425</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15424 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15424</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15424</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the domain parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attack…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15423 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15423</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15423</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the dominio parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15422 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15422</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15422</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the archivo parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15421 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15421</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15421</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the check_ip parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An atta…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15420 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15420</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15420</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.9.8.891. Authentication is not required to exploit this vulnerability. The specific flaw exists within loader_ajax.php. When parsing the line parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can l…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5291 – Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the ker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5291</guid>
    <pubDate>Tue, 31 Mar 2020 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5291</strong></p>
  <p>Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unpri…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-648</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-10230 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10230</guid>
    <pubDate>Mon, 16 Mar 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-10230</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14724 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14724</guid>
    <pubDate>Wed, 11 Sep 2019 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14724</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to edit an e-mail forwarding destination of a victim's account via an attacker account.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13477 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13477</guid>
    <pubDate>Wed, 21 Aug 2019 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13477</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13386 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13386</guid>
    <pubDate>Fri, 26 Jul 2019 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13386</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell with user privilege.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13359 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13359</guid>
    <pubDate>Tue, 16 Jul 2019 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13359</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp directory, and use it to become the root user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13605 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13605</guid>
    <pubDate>Tue, 16 Jul 2019 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13605</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to base64, and thus this is different from CVE-2019-13360.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-13360 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13360</guid>
    <pubDate>Tue, 16 Jul 2019 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-13360</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18773 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18773</guid>
    <pubDate>Tue, 20 Nov 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18773</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18772 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18772</guid>
    <pubDate>Tue, 20 Nov 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18772</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18323 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18323</guid>
    <pubDate>Mon, 15 Oct 2018 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18323</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-18322 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18322</guid>
    <pubDate>Mon, 15 Oct 2018 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-18322</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6926 – In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6926</guid>
    <pubDate>Mon, 12 Feb 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6926</strong></p>
  <p>In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5972 – The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5972</guid>
    <pubDate>Tue, 14 Feb 2017 06:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5972</strong></p>
  <p>The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demonstrated by an attack against the kernel-3.10.0 package in CentOS Linux 7. NOTE: third parties have been unable to discern any relationship…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5425 – The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5425</guid>
    <pubDate>Thu, 13 Oct 2016 14:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5425</strong></p>
  <p>The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5425">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
