Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Pacsone Server HIGH 8.8
CVE-2020-12715

RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.

No fix yet
Fix from $1,950 2020-09-30
Re\ HIGH 7.5
CVE-2020-15488

Re:Desk 2.3 allows insecure file upload.

No fix yet
Fix from $1,950 2020-09-30
Seat Reservation System CRITICAL 9.8
CVE-2020-25763

Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution…

No fix yet
Fix from $2,300 2020-09-30
Pluck HIGH 8.8
CVE-2020-21564

An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin…

No fix yet
Fix from $1,950 2020-09-30
Niushop CRITICAL 9.8
CVE-2020-19672

Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface, through parameter upload, b…

No fix yet
Fix from $2,300 2020-09-30
Observium HIGH 8.8
CVE-2020-25144

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…

Mitigation only
Fix from $1,950 2020-09-25
Observium HIGH 8.8
CVE-2020-25145

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…

Mitigation only
Fix from $1,950 2020-09-25
Observium HIGH 8.8
CVE-2020-25149

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…

Mitigation only
Fix from $1,950 2020-09-25
Observium HIGH 8.8
CVE-2020-25136

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…

No fix yet
Fix from $1,950 2020-09-25
Observium HIGH 8.8
CVE-2020-25134

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…

Mitigation only
Fix from $1,950 2020-09-25
Observium HIGH 8.8
CVE-2020-25133

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…

Mitigation only
Fix from $1,950 2020-09-25
Ismartgate Pro Firmware CRITICAL 9.8
CVE-2020-12843

ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV must be used.

No fix yet
Fix from $2,300 2020-09-24
Ismartgate Pro Firmware HIGH 7.5
CVE-2020-12837

ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG must be used.

No fix yet
Fix from $1,950 2020-09-24
Unified Contact Center Express HIGH 7.2
CVE-2019-1888

A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attack…

Mitigation only
Fix from $1,950 2020-09-23
Simple Library Management System HIGH 7.8
CVE-2020-25515

Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<site>/lms/index.php?page=books.

No fix yet
Fix from $1,950 2020-09-22
Ozeki Ng Sms Gateway HIGH 8.8
CVE-2020-14022

Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a fil…

Fix: after 4.17.6
Fix from $1,950 2020-09-22
Digital Experience Platform MEDIUM 6.5
CVE-2020-15839

Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data PO…

Fix: 7.3.3+
Fix from $1,600 2020-09-22
Data Risk Manager HIGH 8.8
CVE-2020-4620EPSS 5%

IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file e…

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Typesetter HIGH 7.2
CVE-2020-25790EPSS 16%

Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes…

Fix: after 5.1
Fix from $1,950 2020-09-19
Soy Cms HIGH 7.2
CVE-2020-15189

SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was…

Fix: 3.0.2.328+
Fix from $1,950 2020-09-18
Webtareas HIGH 7.5
CVE-2020-25733

webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.

Fix: after 2.1
Fix from $1,950 2020-09-18
Secflow 1v Firmware MEDIUM 6.1
CVE-2020-13260

A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScri…

No fix yet
Fix from $1,600 2020-09-17
Online Course Registration CRITICAL 9.8
CVE-2020-23828

A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the h…

No fix yet
Fix from $2,300 2020-09-15
Spectrum Protect Plus HIGH 8.0
CVE-2020-4703

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be…

Fix: after 10.1.6
Fix from $1,950 2020-09-15
Vtenext HIGH 8.8
CVE-2020-10228

A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execut…

No fix yet
Fix from $1,950 2020-09-14
Pligg HIGH 7.2
CVE-2020-25287

Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admi…

No fix yet
Fix from $1,950 2020-09-13
File Manager CRITICAL 9.8
CVE-2020-25213 KEVEPSS 97%

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it rename…

Fix: 6.9+
Fix from $2,300 2020-09-09
Online Bike Rental CRITICAL 9.1
CVE-2020-24195

An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote…

No fix yet
Fix from $2,300 2020-09-09
Car Rental Project CRITICAL 9.8
CVE-2020-24199

Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote co…

No fix yet
Fix from $2,300 2020-09-09
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2020-6288

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file…

Mitigation only
Fix from $1,600 2020-09-09