Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Logicaldoc CRITICAL 9.8
CVE-2020-9423EPSS 5%

LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. Logic…

Fix: 8.3.3+
Fix from $2,300 2020-03-18
Prtg Network Monitor HIGH 7.2
CVE-2019-11074

A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrar…

Fix: after 19.1.49
Fix from $1,950 2020-03-17
Umbraco Cms MEDIUM 6.5
CVE-2020-9472

Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.

No fix yet
Fix from $1,600 2020-03-16
Umbraco Cms HIGH 8.8
CVE-2020-9471

Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.

No fix yet
Fix from $1,950 2020-03-16
Pandora Fms HIGH 7.2
CVE-2020-5844EPSS 30%

index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP script…

No fix yet
Fix from $1,950 2020-03-16
Acontent HIGH 8.8
CVE-2020-10557

An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section i…

Fix: after 1.4
Fix from $1,950 2020-03-16
Grr HIGH 7.2
CVE-2020-10562

An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.

Fix: 3.4.1c+
Fix from $1,950 2020-03-13
Phpkb HIGH 7.2
CVE-2020-10386EPSS 12%

admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php fi…

No fix yet
Fix from $1,950 2020-03-12
Jce HIGH 8.8
CVE-2015-7339

JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes…

Fix: after 2.5.2
Fix from $1,950 2020-03-09
Jnews HIGH 8.8
CVE-2015-7341

JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.

Fix: 8.5.0+
Fix from $1,950 2020-03-09
Markvision Enterprise CRITICAL 9.8
CVE-2016-6918

Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (

Fix: 2.4.1+
Fix from $2,300 2020-03-09
Bookstack HIGH 8.8
CVE-2020-5256

BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to exe…

Fix: 0.25.3+
Fix from $1,950 2020-03-09
Online Book Store CRITICAL 9.8
CVE-2020-10224EPSS 5%

An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exp…

No fix yet
Fix from $2,300 2020-03-08
Job Portal CRITICAL 9.8
CVE-2020-10225

An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploi…

No fix yet
Fix from $2,300 2020-03-08
Web Tv Player CRITICAL 9.8
CVE-2020-9380

IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script.

Fix: after 2020-02-22
Fix from $2,300 2020-03-05
Fleet Maintenance Management HIGH 8.8
CVE-2018-19798

Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the a…

Fix: after 1.2
Fix from $1,950 2020-03-02
Pandora Fms HIGH 7.2
CVE-2020-8500

In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The ven…

No fix yet
Fix from $1,950 2020-03-02
Jaba Xpress HIGH 8.8
CVE-2018-17058

An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload featu…

Fix: after 2018-09-14
Fix from $1,950 2020-03-02
Kunena CRITICAL 9.8
CVE-2016-11020

Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.

Fix: 5.0.4+
Fix from $2,300 2020-02-25
Dotnetnuke MEDIUM 6.5
CVE-2020-5188

DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.

Fix: after 9.4.4
Fix from $1,600 2020-02-24
Anti Malware Sdk MEDIUM 5.5
CVE-2020-9320

Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for E…

Fix: 8.3.54.138+
Fix from $1,600 2020-02-20
Debian Linux HIGH 8.8
CVE-2015-0258

Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticate…

Fix: 2.1+
Fix from $1,950 2020-02-17
Tinybrowser CRITICAL 9.8
CVE-2011-4908EPSS 56%

TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

Fix: 1.5.13+
Fix from $2,300 2020-02-12
Tinybrowser CRITICAL 9.8
CVE-2011-4906EPSS 10%

Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

Fix: 1.5.13+
Fix from $2,300 2020-02-12
Yabb CRITICAL 9.8
CVE-2013-2057

YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability

Fix: after 2.5.2
Fix from $2,300 2020-02-11
Nextgen Gallery CRITICAL 9.8
CVE-2013-3684EPSS 19%

NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload

Fix: 1.9.13+
Fix from $2,300 2020-02-11
Polarbear Cms CRITICAL 9.8
CVE-2013-0803EPSS 75%

A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.

No fix yet
Fix from $2,300 2020-02-11
Prismview Player 11 CRITICAL 9.8
CVE-2019-20451EPSS 8%

The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requ…

No fix yet
Fix from $2,300 2020-02-10
Creative Contact Form CRITICAL 9.8
CVE-2014-8739EPSS 92%

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Sol…

Fix: 1.0.0 / 2.0.1+
Fix from $2,300 2020-02-08
Vtiger Crm HIGH 8.8
CVE-2013-3591EPSS 43%

vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability

No fix yet
Fix from $1,950 2020-02-07