Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Rails HIGH 7.5
CVE-2020-8162

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows …

Fix: 5.2.4.2 / 6.0.3.1+
Fix from $1,950 2020-06-19
Factorytalk Linx HIGH 7.5
CVE-2020-12005

FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:…

Fix: after 4.11.00
Fix from $1,950 2020-06-15
Spectrum Protect Plus HIGH 8.0
CVE-2020-4470

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be…

Fix: after 10.1.5
Fix from $1,950 2020-06-15
Navigatecms CRITICAL 9.8
CVE-2020-14067

The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may con…

Patch available
Fix from $2,300 2020-06-15
Vera HIGH 7.2
CVE-2019-15123

The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a m…

Mitigation only
Fix from $1,950 2020-06-12
Pandora Fms HIGH 7.2
CVE-2020-13852EPSS 28%

Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.

No fix yet
Fix from $1,950 2020-06-11
Pandora Fms HIGH 7.2
CVE-2020-13855EPSS 28%

Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.

No fix yet
Fix from $1,950 2020-06-11
Drag And Drop Multiple File Upload Contact Form 7 CRITICAL 9.8
CVE-2020-12800EPSS 79%

The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution b…

Fix: 1.3.3.3+
Fix from $2,300 2020-06-08
Phantompdf MEDIUM 6.5
CVE-2018-21243

An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used.

Fix: 8.3.6+
Fix from $1,600 2020-06-04
Phantompdf CRITICAL 9.8
CVE-2018-21244

An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded executable file in a PDF portfoli…

Fix: 8.3.6+
Fix from $2,300 2020-06-04
Zimbra Collaboration Suite HIGH 8.0
CVE-2020-12846

Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is potential abuse of /service/uplo…

Fix: 8.8.15+
Fix from $1,950 2020-06-03
Mappress HIGH 8.8
CVE-2020-12675

The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related t…

Fix: 2.54.6+
Fix from $1,950 2020-05-29
Dext5 CRITICAL 9.8
CVE-2020-13442

A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp hand…

Fix: after 2.7.1402870
Fix from $2,300 2020-05-25
Monstra HIGH 8.8
CVE-2020-13384

Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example…

No fix yet
Fix from $1,950 2020-05-22
Windows 10 HIGH 8.5
CVE-2020-1112

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded…

Patch available
Fix from $1,950 2020-05-21
Sharepoint Enterprise Server HIGH 8.8
CVE-2020-1102EPSS 5%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An…

Patch available
Fix from $1,950 2020-05-21
Sharepoint Enterprise Server HIGH 8.8
CVE-2020-1023

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An…

Patch available
Fix from $1,950 2020-05-21
Sharepoint Enterprise Server HIGH 8.8
CVE-2020-1024

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An…

Patch available
Fix from $1,950 2020-05-21
Virtual Private Network Software Development Kit CRITICAL 9.8
CVE-2020-12828

An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localho…

Fix: 1.3.3.218+
Fix from $2,300 2020-05-21
Microweber HIGH 7.8
CVE-2020-13241

Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (u…

No fix yet
Fix from $1,950 2020-05-20
Newscoop HIGH 7.8
CVE-2020-11807

Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP cod…

Patch available
Fix from $1,950 2020-05-19
Rconfig HIGH 8.8
CVE-2020-12255EPSS 53%

rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file uplo…

Mitigation only
Fix from $1,950 2020-05-18
Gwtupload HIGH 7.5
CVE-2020-13128

An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that ca…

No fix yet
Fix from $1,950 2020-05-18
Elementor Page Builder CRITICAL 9.9
CVE-2020-13126EPSS 9%

An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-131…

Fix: 2.9.4+
Fix from $2,300 2020-05-17
Movable Type HIGH 8.8
CVE-2020-5577

Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Adv…

Fix: after 7.2.1
Fix from $1,950 2020-05-14
Pi Hole HIGH 8.8
CVE-2020-11108EPSS 78%

The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution …

Fix: after 4.4
Fix from $1,950 2020-05-11
Big Ip Access Policy Manager HIGH 7.1
CVE-2020-5880

Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, b…

Fix: after 15.0.1.3
Fix from $1,950 2020-04-30
Open Audit HIGH 8.8
CVE-2020-11943EPSS 24%

An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.

No fix yet
Fix from $1,950 2020-04-29
Gigavue MEDIUM 6.2
CVE-2020-12252

An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an execu…

Fix: 5.4.04 / 5.5.02+
Fix from $1,600 2020-04-29
Rukovoditel CRITICAL 9.8
CVE-2020-11817

In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacke…

No fix yet
Fix from $2,300 2020-04-27