Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Ucms CRITICAL 9.8
CVE-2020-25537

File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.

No fix yet
Fix from $2,300 2020-11-30
Drupal HIGH 8.8
CVE-2020-13671 KEV

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and …

Fix: 7.74 / 8.8.11+
Fix from $1,950 2020-11-20
Webreports HIGH 8.8
CVE-2020-7569

A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could ca…

Fix: after 3.1
Fix from $1,950 2020-11-19
Lemocms HIGH 7.3
CVE-2020-25406

app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files.

Fix: after 1.8.7
Fix from $1,950 2020-11-18
Online Library Management System CRITICAL 9.8
CVE-2020-28130EPSS 7%

An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code …

No fix yet
Fix from $2,300 2020-11-17
Controller CRITICAL 9.8
CVE-2020-26553

An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web …

No fix yet
Fix from $2,300 2020-11-17
Tourism Management System HIGH 8.8
CVE-2020-28136

An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/cre…

No fix yet
Fix from $1,950 2020-11-17
Online Clothing Store CRITICAL 9.8
CVE-2020-28140

SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php.

No fix yet
Fix from $2,300 2020-11-17
Artworks Gallery In Php\, Css\, Javascript\, And Mysql HIGH 8.8
CVE-2020-28687EPSS 12%

The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

No fix yet
Fix from $1,950 2020-11-17
Artworks Gallery In Php\, Css\, Javascript\, And Mysql HIGH 8.8
CVE-2020-28688EPSS 12%

The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

No fix yet
Fix from $1,950 2020-11-17
Horizontcms HIGH 8.8
CVE-2020-28693

An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploadin…

No fix yet
Fix from $1,950 2020-11-16
Gila Cms HIGH 7.2
CVE-2020-28692

In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.

No fix yet
Fix from $1,950 2020-11-16
Endpoint Manager CRITICAL 9.9
CVE-2020-13774

An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r…

Mitigation only
Fix from $2,300 2020-11-12
Flexdotnetcms HIGH 8.8
CVE-2020-27386EPSS 73%

An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by usi…

Fix: 1.5.9+
Fix from $1,950 2020-11-12
Sentrifugo HIGH 8.8
CVE-2020-26803

In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload…

No fix yet
Fix from $1,950 2020-11-12
Sentrifugo HIGH 8.8
CVE-2020-26804

In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with t…

No fix yet
Fix from $1,950 2020-11-12
Netweaver Application Server Java HIGH 7.2
CVE-2020-26820

SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator …

No fix yet
Fix from $1,950 2020-11-10
Microweber CRITICAL 9.8
CVE-2020-23138

An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extensio…

Mitigation only
Fix from $2,300 2020-11-09
Magento CRITICAL 9.1
CVE-2020-24407EPSS 5%

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. T…

Fix: 2.3.5+
Fix from $2,300 2020-11-09
Suitecrm HIGH 8.8
CVE-2020-28328EPSS 63%

SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admi…

Fix: 7.11.17+
Fix from $1,950 2020-11-06
Horizontcms HIGH 8.8
CVE-2020-27387EPSS 18%

An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to uploa…

Patch available
Fix from $1,950 2020-11-05
Basercms HIGH 7.2
CVE-2020-15277

baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading …

Fix: 4.4.1+
Fix from $1,950 2020-10-30
I2 Ibase HIGH 7.8
CVE-2020-4588

IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code …

Fix: after 8.9.13
Fix from $1,950 2020-10-30
Bmc Firmware CRITICAL 9.8
CVE-2020-11486

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows a…

Fix: 3.38.30+
Fix from $2,300 2020-10-29
Connect Secure HIGH 7.2
CVE-2020-8260 KEVEPSS 96%

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution …

Fix: after 9.0
Fix from $1,950 2020-10-28
Car Rental Management System CRITICAL 9.8
CVE-2020-27956EPSS 5%

An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code exec…

No fix yet
Fix from $2,300 2020-10-28
Ucms CRITICAL 9.8
CVE-2020-25483EPSS 9%

An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the s…

No fix yet
Fix from $2,300 2020-10-23
Adaptive Security Appliance HIGH 8.6
CVE-2020-3436

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allo…

Fix: 6.3.0.6 / 6.4.0.10+
Fix from $1,950 2020-10-21
Sage Dpw MEDIUM 6.1
CVE-2020-26583

An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses c…

Fix: 2020_06_002+
Fix from $1,600 2020-10-16
Cuppacms HIGH 8.8
CVE-2020-26048

The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and throu…

Fix: 2019-11-12+
Fix from $1,950 2020-10-05