<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – CentOS</title>
  <link>https://cvedaily.com/pages/tags/centos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/centos.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – CentOS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:03 +0000</lastBuildDate>
  <item>
    <title>[Unknown] CVE-2023-54236 – In the Linux kernel, the following vulnerability has been resolved:

net/net_fai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54236</guid>
    <pubDate>Tue, 30 Dec 2025 13:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2023-54236</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net/net_failover: fix txq exceeding warning  The failover txq is inited as 16 queues. when a packet is transmitted from the failover device firstly, the failover device will select the queue which is returned from the primary device if the primary device is UP and running. If the primary device txq is bigger than the default 16,…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-48703 – CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48703</guid>
    <pubDate>Fri, 19 Sep 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-48703</strong></p>
  <p>CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-3498 – An unauthenticated user with management network access can get and 
modify the R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3498</guid>
    <pubDate>Wed, 09 Jul 2025 09:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-3498</strong></p>
  <p>An unauthenticated user with management network access can get and  modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20)  configuration. The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). An attacker can use these APIs to get access to all system settings, modify the configuration and execute some commands (e.g., sy…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3497 – The Linux distribution underlying the Radiflow iSAP Smart Collector 
(CentOS 7 -...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3497</guid>
    <pubDate>Wed, 09 Jul 2025 09:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3497</strong></p>
  <p>The Linux distribution underlying the Radiflow iSAP Smart Collector  (CentOS 7 - VSAP 1.20) is obsolete and  reached end of life (EOL) on June 30, 2024.  Thus, any  unmitigated vulnerability could be exploited to affect this product.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-1104</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27028 – The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27028</guid>
    <pubDate>Wed, 09 Jul 2025 09:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27028</strong></p>
  <p>The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging to other users and having restricted access (like, for example, the root password hash).</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44877 – login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44877</guid>
    <pubDate>Thu, 05 Jan 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44877</strong></p>
  <p>login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45467 – In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45467</guid>
    <pubDate>Mon, 26 Dec 2022 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45467</strong></p>
  <p>In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45466 – In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45466</guid>
    <pubDate>Mon, 26 Dec 2022 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45466</strong></p>
  <p>In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-41352 – An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41352</guid>
    <pubDate>Mon, 26 Sep 2022 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-41352</strong></p>
  <p>An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red H…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-4218 – A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4218</guid>
    <pubDate>Wed, 24 Aug 2022 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-4218</strong></p>
  <p>A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panics the system. This flaw allows a local attacker with local access to cause a denial of service while the system reboots. The issue is specific to CentOS/RHEL.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-20315 – A locking protection bypass flaw was found in some versions of gnome-shell as sh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20315</guid>
    <pubDate>Fri, 18 Feb 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-20315</strong></p>
  <p>A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked user, even if the session is still locked.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43816 – containerd is an open source container runtime. On installations using SELinux, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43816</guid>
    <pubDate>Wed, 05 Jan 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43816</strong></p>
  <p>containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved b…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34424 – A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34424</guid>
    <pubDate>Wed, 24 Nov 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34424</strong></p>
  <p>A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-34423 – A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34423</guid>
    <pubDate>Wed, 24 Nov 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-34423</strong></p>
  <p>A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41034 – The build of some language stacks of Eclipse Che version 6 includes pulling some...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41034</guid>
    <pubDate>Wed, 29 Sep 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41034</strong></p>
  <p>The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with arbitrary ones. The stacks involved are Java 8 (alpine and centos), Android and PHP. The vulnerability is not exploitable at runtime but only whe…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-924</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-31324 – The unprivileged user portal part of CentOS Web Panel is affected by a Command I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31324</guid>
    <pubDate>Tue, 18 May 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-31324</strong></p>
  <p>The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-31316 – The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31316</guid>
    <pubDate>Tue, 18 May 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-31316</strong></p>
  <p>The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15628 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15628</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15628</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mail_autoreply.php. When parsing the user parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. A…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15627 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15627</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15627</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mail_autoreply.php. When parsing the account parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15626 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15626</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15626</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the term parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An att…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15625 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15625</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15625</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_add_mailbox.php. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15624 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15624</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15624</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_new_account.php. When parsing the domain parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15623 – This vulnerability allows remote attackers to write arbitrary files on affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15623</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15623</strong></p>
  <p>This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the archivo parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15622 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15622</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15622</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mail_autoreply.php. When parsing the search parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15621 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15621</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15621</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mail_autoreply.php. When parsing the email parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15620 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15620</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15620</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the id parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15619 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15619</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15619</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the type parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15618 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15618</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15618</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15617 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15617</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15617</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the status parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15616 – This vulnerability allows remote attackers to disclose sensitive information on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15616</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15616</strong></p>
  <p>This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the package parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15615 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15615</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15615</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_ftp_manager.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage thi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15614 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15614</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15614</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the cha parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15613 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15613</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15613</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_admin_apis.php. When parsing the line parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker c…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15612 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15612</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15612</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_ftp_manager.php. When parsing the userLogin parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An atta…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15611 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15611</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15611</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_restart parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15610 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15610</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15610</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the modulo parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker c…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15609 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15609</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15609</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_stop parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An att…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15608 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15608</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15608</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the ai_service parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15607 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15607</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15607</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_admin_apis.php. When parsing the line parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker c…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15606 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15606</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15606</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_admin_apis.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15435 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15435</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15435</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_start parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An at…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15434 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15434</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15434</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the canal parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker ca…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15433 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15433</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15433</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the phpversion parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attack…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15432 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15432</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15432</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_migration_cpanel.php. When parsing the filespace parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15431 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15431</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15431</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_crons.php. When parsing the user parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can le…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15430 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15430</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15430</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An att…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15429 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15429</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15429</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_crons.php. When parsing the user parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can le…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15428 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15428</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15428</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_crons.php. When parsing the line parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can le…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15427 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15427</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15427</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_disk_usage.php. When parsing the folderName parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An atta…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15426 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15426</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15426</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_migration_cpanel.php. When parsing the serverip parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15425 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15425</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15425</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15424 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15424</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15424</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the domain parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attack…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15423 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15423</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15423</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the dominio parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15422 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15422</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15422</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the archivo parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15421 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15421</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15421</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the check_ip parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An atta…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15420 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15420</guid>
    <pubDate>Tue, 28 Jul 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15420</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.9.8.891. Authentication is not required to exploit this vulnerability. The specific flaw exists within loader_ajax.php. When parsing the line parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can l…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5291 – Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the ker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5291</guid>
    <pubDate>Tue, 31 Mar 2020 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5291</strong></p>
  <p>Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unpri…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-648</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-10230 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10230</guid>
    <pubDate>Mon, 16 Mar 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-10230</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15235 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15235</guid>
    <pubDate>Tue, 17 Dec 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15235</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/sess_xxxxxx, and the victim's token value from /usr/local/cwpsrv/logs/access_log, then use them to gain access to the victim's password (for the OS and phpMyAdmin) via an attacker account. This is different from CVE-2019-14782.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14782 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14782</guid>
    <pubDate>Tue, 17 Dec 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14782</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the /tmp directory, and the victim's token value from /usr/local/cwpsrv/logs/access_log, then use them to make a request to extract the victim's password (for the OS and phpMyAdmin) via an attacker account.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-16295 – Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16295</guid>
    <pubDate>Thu, 31 Oct 2019 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-16295</strong></p>
  <p>Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmd_arg parameter. This can be exploited by a local attacker who supplies a crafted filename within a directory visited by the victim.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14725 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14725</guid>
    <pubDate>Wed, 11 Sep 2019 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14725</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change the e-mail usage value of a victim account via an attacker account.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14724 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14724</guid>
    <pubDate>Wed, 11 Sep 2019 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14724</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to edit an e-mail forwarding destination of a victim's account via an attacker account.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14730 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14730</guid>
    <pubDate>Tue, 10 Sep 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14730</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a domain from a victim's account via an attacker account.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14729 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14729</guid>
    <pubDate>Tue, 10 Sep 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14729</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a sub-domain from a victim's account via an attacker account.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14728 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14728</guid>
    <pubDate>Tue, 10 Sep 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14728</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to add an e-mail forwarding destination to a victim's account via an attacker account.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14727 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14727</guid>
    <pubDate>Tue, 10 Sep 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14727</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change the e-mail password of a victim account via an attacker account.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14726 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14726</guid>
    <pubDate>Tue, 10 Sep 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14726</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to access and delete DNS records of a victim's account via an attacker account.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14723 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14723</guid>
    <pubDate>Tue, 10 Sep 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14723</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a victim's e-mail account via an attacker account.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14722 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14722</guid>
    <pubDate>Tue, 10 Sep 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14722</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete an e-mail forwarding destination from a victim's account via an attacker account.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14721 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14721</guid>
    <pubDate>Tue, 10 Sep 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14721</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a target user from phpMyAdmin via an attacker account.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-13476 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13476</guid>
    <pubDate>Wed, 21 Aug 2019 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-13476</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to achieve root access via the email list page.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14246 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14246</guid>
    <pubDate>Wed, 21 Aug 2019 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14246</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14245 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14245</guid>
    <pubDate>Wed, 21 Aug 2019 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14245</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-13599 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13599</guid>
    <pubDate>Wed, 21 Aug 2019 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-13599</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a username is valid by comparing response times.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13477 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13477</guid>
    <pubDate>Wed, 21 Aug 2019 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13477</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-13387 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13387</guid>
    <pubDate>Fri, 26 Jul 2019 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-13387</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fm_current_dir) allows attackers to steal a cookie or session, or redirect to a phishing website.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13386 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13386</guid>
    <pubDate>Fri, 26 Jul 2019 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13386</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell with user privilege.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-13385 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13385</guid>
    <pubDate>Fri, 26 Jul 2019 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-13385</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allows attackers to enumerate users and check for active users of the application by reading /tmp/login.log.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13359 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13359</guid>
    <pubDate>Tue, 16 Jul 2019 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13359</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp directory, and use it to become the root user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13605 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13605</guid>
    <pubDate>Tue, 16 Jul 2019 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13605</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to base64, and thus this is different from CVE-2019-13360.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-13383 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13383</guid>
    <pubDate>Tue, 16 Jul 2019 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-13383</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-13360 – In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13360</guid>
    <pubDate>Tue, 16 Jul 2019 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-13360</strong></p>
  <p>In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-12190 – XSS was discovered in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12190</guid>
    <pubDate>Tue, 21 May 2019 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-12190</strong></p>
  <p>XSS was discovered in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.747 via the testacc/fileManager2.php fm_current_dir or filename parameter.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-11429 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11429</guid>
    <pubDate>Mon, 13 May 2019 15:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-11429</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to Reflected XSS for the "Domain" field on the "DNS Functions > "Add DNS Zone" screen.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-10893 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10893</guid>
    <pubDate>Thu, 18 Apr 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-10893</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Settings > "Edit Settings" screen. By changing the email ID to any XSS Payload and clicking on Save Changes, the XSS Payload will execute.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-10261 – CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10261</guid>
    <pubDate>Wed, 03 Apr 2019 15:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-10261</strong></p>
  <p>CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit Nameservers IPs" action.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-7646 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7646</guid>
    <pubDate>Tue, 26 Mar 2019 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-7646</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-18774 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18774</guid>
    <pubDate>Tue, 20 Nov 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-18774</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18773 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18773</guid>
    <pubDate>Tue, 20 Nov 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18773</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18772 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18772</guid>
    <pubDate>Tue, 20 Nov 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18772</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-18324 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18324</guid>
    <pubDate>Mon, 15 Oct 2018 07:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-18324</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, or file (within the file_editor) parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18323 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18323</guid>
    <pubDate>Mon, 15 Oct 2018 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18323</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-18322 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18322</guid>
    <pubDate>Mon, 15 Oct 2018 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-18322</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-17977 – The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17977</guid>
    <pubDate>Mon, 08 Oct 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-17977</strong></p>
  <p>The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6926 – In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6926</guid>
    <pubDate>Mon, 12 Feb 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6926</strong></p>
  <p>In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-5962 – index.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5962</guid>
    <pubDate>Mon, 22 Jan 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-5962</strong></p>
  <p>index.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the id parameter to the phpini_editor module or the email_address parameter to the mail_add-new module.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-5961 – CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5961</guid>
    <pubDate>Mon, 22 Jan 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-5961</strong></p>
  <p>CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the `module` value of the `index.php` file.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5972 – The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5972</guid>
    <pubDate>Tue, 14 Feb 2017 06:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5972</strong></p>
  <p>The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demonstrated by an attack against the kernel-3.10.0 package in CentOS Linux 7. NOTE: third parties have been unable to discern any relationship…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5425 – The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5425</guid>
    <pubDate>Thu, 13 Oct 2016 14:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5425</strong></p>
  <p>The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5425">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
