Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Concrete Cms HIGH 7.2
CVE-2020-24986

Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to mo…

Fix: after 8.5.2
Fix from $1,950 2020-09-04
Manageengine Applications Manager HIGH 7.2
CVE-2020-14008EPSS 40%

Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which l…

Fix: after 13.0
Fix from $1,950 2020-09-04
Autoptimize HIGH 7.2
CVE-2020-24948EPSS 13%

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high pri…

Fix: 2.7.7+
Fix from $1,950 2020-09-03
Maracms HIGH 7.2
CVE-2020-25042EPSS 18%

An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session …

No fix yet
Fix from $1,950 2020-09-03
Dolibarr HIGH 8.8
CVE-2020-14209EPSS 27%

Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht a…

Fix: 11.0.5+
Fix from $1,950 2020-09-02
Librehealth Ehr HIGH 8.8
CVE-2020-23829

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers …

No fix yet
Fix from $1,950 2020-09-01
House Rental And Property Listing Project CRITICAL 9.8
CVE-2020-24202

File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote…

No fix yet
Fix from $2,300 2020-08-27
Travel Management System CRITICAL 9.8
CVE-2020-24203

Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1…

No fix yet
Fix from $2,300 2020-08-27
Online Bike Rental HIGH 7.2
CVE-2020-24196

An Arbitrary File Upload in Vehicle Image Upload in Online Bike Rental v1.0 allows authenticated admin to conduct remote code execution.

No fix yet
Fix from $1,950 2020-08-27
Gmapfp HIGH 7.5
CVE-2020-23972EPSS 31%

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can al…

No fix yet
Fix from $1,950 2020-08-27
Qconvergeconsole HIGH 8.8
CVE-2020-15645EPSS 11%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authent…

Fix: 5.5.00.73+
Fix from $1,950 2020-08-25
Wpdiscuz CRITICAL 10.0
CVE-2020-24186EPSS 95%

A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to u…

Fix: after 7.0.4
Fix from $2,300 2020-08-24
Pnotes.net HIGH 7.8
CVE-2020-22721

A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " E…

No fix yet
Fix from $1,950 2020-08-14
Rapid Scada HIGH 7.8
CVE-2020-22722

Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker …

No fix yet
Fix from $1,950 2020-08-14
Cms Made Simple HIGH 7.8
CVE-2020-17462

CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16…

No fix yet
Fix from $1,950 2020-08-14
Data Loss Prevention MEDIUM 6.4
CVE-2020-7302

Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to …

Fix: 11.3.28 / 11.4.200+
Fix from $1,600 2020-08-13
Netweaver Knowledge Management MEDIUM 6.5
CVE-2020-6293

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to ac…

Mitigation only
Fix from $1,600 2020-08-12
Firefox Esr MEDIUM 5.5
CVE-2020-15649

Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actua…

Fix: 68.11+
Fix from $1,600 2020-08-10
Flatcore HIGH 7.2
CVE-2020-17452

flatCore before 1.5.7 allows upload and execution of a .php file by an admin.

Fix: 1.5.7+
Fix from $1,950 2020-08-09
Openclinic Ga HIGH 8.8
CVE-2020-14488

OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to upload and execute arbitrary file…

Mitigation only
Fix from $1,950 2020-07-29
Concrete Cms HIGH 7.2
CVE-2020-11476

Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.

Fix: 8.5.3+
Fix from $1,950 2020-07-28
Mimevalidator HIGH 8.8
CVE-2020-9309

Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML co…

Fix: 2.0.0 / 4.6.0+
Fix from $1,950 2020-07-15
Neprofile HIGH 8.8
CVE-2020-12854

A remote code execution vulnerability was identified in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can invoke code execution upon up…

No fix yet
Fix from $1,950 2020-07-15
Mail Server MEDIUM 6.5
CVE-2020-14065

IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.

Mitigation only
Fix from $1,600 2020-07-15
Mail Server HIGH 8.8
CVE-2020-14066

IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.

Mitigation only
Fix from $1,950 2020-07-15
Bond HIGH 7.5
CVE-2020-1469

A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial of Service Vulnerability'.

Patch available
Fix from $1,950 2020-07-14
Jira MEDIUM 6.5
CVE-2019-20897

The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a cr…

Fix: 8.5.4 / 8.6.2+
Fix from $1,600 2020-07-13
Mods For Hesk HIGH 8.8
CVE-2020-13994EPSS 7%

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of i…

Fix: after 2019.1.0
Fix from $1,950 2020-07-09
Expressionengine HIGH 8.8
CVE-2020-13443

ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Sav…

Fix: 5.3.2+
Fix from $1,950 2020-06-24
Kordil Edms HIGH 8.8
CVE-2020-13887

documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to the documents folder.

Fix: 2.2.60+
Fix from $1,950 2020-06-22