Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Vtiger Crm HIGH 8.8
CVE-2015-6000EPSS 40%

Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.p…

Fix: after 6.3.0
Fix from $1,950 2020-02-06
Openvas Manager HIGH 8.8
CVE-2011-1597

OpenVAS Manager v2.0.3 allows plugin remote code execution.

No fix yet
Fix from $1,950 2020-02-06
Dotcms CRITICAL 9.8
CVE-2020-6754EPSS 95%

dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $…

Fix: 5.2.4+
Fix from $2,300 2020-02-05
Intrexx CRITICAL 9.8
CVE-2014-2025

Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x…

Mitigation only
Fix from $2,300 2020-01-31
Simplejobscript CRITICAL 9.8
CVE-2020-8440

controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a r…

Fix: after 1.66
Fix from $2,300 2020-01-31
Wemo Switch Firmware CRITICAL 9.8
CVE-2013-2748EPSS 13%

Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.

No fix yet
Fix from $2,300 2020-01-28
Super File Explorer HIGH 8.8
CVE-2020-7998

An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the develope…

Mitigation only
Fix from $1,950 2020-01-28
Manageengine Desktop Central CRITICAL 9.8
CVE-2013-7390EPSS 75%

Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attacke…

Fix: after 8.0.0
Fix from $2,300 2020-01-27
Apexpro Telemetry Server Firmware CRITICAL 9.9
CVE-2020-6965

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, …

Fix: after 4.2
Fix from $2,300 2020-01-24
Wp Gpx Maps CRITICAL 9.8
CVE-2012-6649EPSS 16%

WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.

Mitigation only
Fix from $2,300 2020-01-23
Control HIGH 7.2
CVE-2019-16514

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administra…

No fix yet
Fix from $1,950 2020-01-23
Prestashop HIGH 8.8
CVE-2013-6358

PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ …

No fix yet
Fix from $1,950 2020-01-23
Prizm Content Connect CRITICAL 9.8
CVE-2012-5190

Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability

No fix yet
Fix from $2,300 2020-01-21
Qdpm HIGH 8.8
CVE-2020-7246EPSS 83%

A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo fu…

Fix: after 9.1
Fix from $1,950 2020-01-21
Aware Callmanager HIGH 8.8
CVE-2019-20385

The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content…

No fix yet
Fix from $1,950 2020-01-21
Revenue Management And Billing MEDIUM 5.4
CVE-2020-2730

Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: File Uplo…

Patch available
Fix from $1,600 2020-01-15
Joomla\! MEDIUM 5.3
CVE-2011-4907

Joomla! 1.5x through 1.5.12: Missing JEXEC Check

Fix: after 1.5.12
Fix from $1,600 2020-01-15
Websitebaker HIGH 7.2
CVE-2011-2933

An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files…

Fix: after 2.8.1
Fix from $1,950 2020-01-14
Car Rental Portal HIGH 7.2
CVE-2020-5509EPSS 6%

PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image.

No fix yet
Fix from $1,950 2020-01-14
Employee Records System HIGH 7.2
CVE-2019-20183EPSS 8%

uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the cli…

Mitigation only
Fix from $1,950 2020-01-09
Mapserver HIGH 8.1
CVE-2012-2950

Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP c…

Fix: 3.0.6+
Fix from $1,950 2020-01-09
Invision Power Board CRITICAL 9.8
CVE-2012-2226EPSS 7%

Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute…

Fix: 3.3.1+
Fix from $2,300 2020-01-09
Bss Continuty Cms CRITICAL 9.8
CVE-2014-3448

BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload

No fix yet
Fix from $2,300 2020-01-09
Dedecms HIGH 8.8
CVE-2015-4553EPSS 57%

A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.

Fix: after 5.6
Fix from $1,950 2020-01-06
Fatca CRITICAL 9.9
CVE-2015-5951

A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to…

Fix: 5.2+
Fix from $2,300 2020-01-06
Cloud Backup Suite HIGH 8.8
CVE-2020-5846

An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with t…

No fix yet
Fix from $1,950 2020-01-06
Gila Cms CRITICAL 9.1
CVE-2020-5514EPSS 44%

Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.

No fix yet
Fix from $2,300 2020-01-06
Netcharts Server CRITICAL 9.8
CVE-2014-8516EPSS 82%

Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with a…

No fix yet
Fix from $2,300 2020-01-03
Helpdezk CRITICAL 9.8
CVE-2014-8337

Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to ex…

Fix: after 1.0.1
Fix from $2,300 2020-01-03
Tiny File Manager HIGH 8.8
CVE-2019-16790

In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.

Fix: 2.3.9+
Fix from $1,950 2019-12-30