Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Mappress HIGH 8.8
CVE-2020-12077EPSS 6%

The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability chec…

Fix: 2.53.9+
Fix from $1,950 2020-04-23
Elementor Page Builder CRITICAL 9.9
CVE-2020-7055

An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to exe…

Fix: after 2.7.4
Fix from $2,300 2020-04-22
Phproject HIGH 8.8
CVE-2020-11011

In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arbitrary code. This is patched …

Fix: 1.7.8+
Fix from $1,950 2020-04-22
On Premise CRITICAL 9.8
CVE-2020-10569

SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticate…

No fix yet
Fix from $2,300 2020-04-21
Qdpm CRITICAL 9.8
CVE-2020-11811

In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type va…

No fix yet
Fix from $2,300 2020-04-16
Rukovoditel CRITICAL 9.8
CVE-2020-11815

In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can…

No fix yet
Fix from $2,300 2020-04-16
Silverstripe HIGH 7.5
CVE-2020-9280

In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder inste…

Fix: after 4.5.0
Fix from $1,950 2020-04-15
Sharepoint Enterprise Server HIGH 8.8
CVE-2020-0971EPSS 13%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $1,950 2020-04-15
Sharepoint Enterprise Server HIGH 8.8
CVE-2020-0974EPSS 11%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $1,950 2020-04-15
Sharepoint Enterprise Server HIGH 8.8
CVE-2020-0929EPSS 11%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $1,950 2020-04-15
Business Productivity Servers HIGH 8.8
CVE-2020-0931EPSS 11%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $1,950 2020-04-15
Sharepoint Enterprise Server HIGH 8.8
CVE-2020-0932EPSS 31%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $1,950 2020-04-15
Sharepoint Enterprise Server HIGH 8.8
CVE-2020-0920EPSS 10%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $1,950 2020-04-15
The School Manage System CRITICAL 9.8
CVE-2020-10507

The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Unrestricted file upload (RCE) , that woul…

Mitigation only
Fix from $2,300 2020-04-15
Dungeon Crawl Stone Soup CRITICAL 9.8
CVE-2020-11722

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .…

Fix: 0.25+
Fix from $2,300 2020-04-12
Webaccess\/nms CRITICAL 9.8
CVE-2020-10621

Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).

Fix: 3.0.2+
Fix from $2,300 2020-04-09
Cipace CRITICAL 9.8
CVE-2020-11598

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and exe…

Fix: 9.1+
Fix from $2,300 2020-04-06
Official Car Rental System HIGH 7.2
CVE-2020-11544

An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account bec…

No fix yet
Fix from $1,950 2020-04-06
Testlink HIGH 8.8
CVE-2020-8639EPSS 16%

An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a f…

Patch available
Fix from $1,950 2020-04-03
Microstrategy Web HIGH 7.2
CVE-2020-11451

The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files with arbit…

Fix: after 10.4
Fix from $1,950 2020-04-02
Lifterlms CRITICAL 9.8
CVE-2020-6008

LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution

Fix: 3.37.15+
Fix from $2,300 2020-03-31
Laravel Administrator HIGH 7.2
CVE-2020-10963EPSS 15%

FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/f…

Fix: after 5.0.12
Fix from $1,950 2020-03-25
Serendipity CRITICAL 9.8
CVE-2020-10964

Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This…

Fix: 2.3.4+
Fix from $2,300 2020-03-25
Acymailing HIGH 7.2
CVE-2020-10934

Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.

Fix: 6.9.2+
Fix from $1,950 2020-03-24
Debian Linux MEDIUM 6.5
CVE-2020-8866EPSS 10%

This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authenticat…

Fix: 2.0.20+
Fix from $1,600 2020-03-23
Pandora Fms HIGH 7.2
CVE-2020-7935

Artica Pandora FMS through 7.42 is vulnerable to remote PHP code execution because of an Unrestricted Upload Of A File With A Dangerous Type issue in…

Fix: after 7.42
Fix from $1,950 2020-03-23
Pandora Fms HIGH 7.2
CVE-2020-8511

In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a differen…

Fix: after 7.42
Fix from $1,950 2020-03-23
Ez Publish Kernel CRITICAL 9.8
CVE-2020-10806

eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 20…

Fix: 5.4.14.1 / 6.13.6.2+
Fix from $2,300 2020-03-22
Cms Made Simple HIGH 7.8
CVE-2020-10682

The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinter…

No fix yet
Fix from $1,950 2020-03-20
Enigma Network Management Solution HIGH 8.8
CVE-2019-16066

An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attac…

Fix: after 65.0.0
Fix from $1,950 2020-03-19