Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Omnivista 8770 HIGH 7.2
CVE-2019-20048EPSS 6%

An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web …

Fix: 4.1.12+
Fix from $1,950 2019-12-27
Reviewboard HIGH 8.8
CVE-2013-4796

ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request

Mitigation only
Fix from $1,950 2019-12-27
SQLite HIGH 7.5
CVE-2019-19925EPSS 7%

zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.

Fix: 1.0.1.1+
Fix from $1,950 2019-12-24
Upload Image With Ajax CRITICAL 9.8
CVE-2019-8293

Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.

Patch available
Fix from $2,300 2019-12-23
K2 CRITICAL 9.8
CVE-2019-19634

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .ph…

Fix: 1.0.3 / 2.0.4+
Fix from $2,300 2019-12-17
Contao HIGH 8.8
CVE-2019-19745

Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute th…

Fix: after 4.8.5
Fix from $1,950 2019-12-17
Sppa T3000 Ms3000 Migration Server CRITICAL 9.8
CVE-2019-18313

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could …

Mitigation only
Fix from $2,300 2019-12-12
Sppa T3000 Application Server HIGH 7.5
CVE-2019-18320

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…

Mitigation only
Fix from $1,950 2019-12-12
Sppa T3000 Application Server HIGH 8.8
CVE-2019-18288

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with valid authentication at…

No fix yet
Fix from $1,950 2019-12-12
Solismed CRITICAL 9.8
CVE-2019-15936

Intesync Solismed 3.3sp allows Insecure File Upload.

No fix yet
Fix from $2,300 2019-12-12
Planning Analytics HIGH 8.8
CVE-2019-4612

IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malici…

Mitigation only
Fix from $1,950 2019-12-09
Nopcommerce HIGH 8.8
CVE-2019-19684

nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/Facebook…

No fix yet
Fix from $1,950 2019-12-09
Struts HIGH 8.8
CVE-2012-1592EPSS 29%

A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit…

Mitigation only
Fix from $1,950 2019-12-05
Prestashop CRITICAL 9.8
CVE-2019-19594

reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute…

No fix yet
Fix from $2,300 2019-12-05
Prestashop CRITICAL 9.8
CVE-2019-19595

reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers…

No fix yet
Fix from $2,300 2019-12-05
Remedy Smart Reporting MEDIUM 6.5
CVE-2019-11216

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attack…

Fix: after 19.02.01
Fix from $1,600 2019-12-04
K2 CRITICAL 9.8
CVE-2019-19576EPSS 26%

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar…

Fix: 1.0.3 / 2.0.4+
Fix from $2,300 2019-12-04
Cloud Pak System HIGH 8.8
CVE-2019-4130

IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary cod…

Patch available
Fix from $1,950 2019-12-03
Webtitan HIGH 7.2
CVE-2019-19020

An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted backup file that enab…

Fix: 5.18+
Fix from $1,950 2019-12-02
Xperience MEDIUM 5.4
CVE-2019-19493

Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.

Fix: 12.0.50+
Fix from $1,600 2019-12-02
Free Photo Viewer HIGH 7.8
CVE-2019-19468

Free Photo Viewer 1.3 allows remote attackers to execute arbitrary code via a crafted BMP and/or TIFF file that triggers a malformed SEH, as demonstr…

No fix yet
Fix from $1,950 2019-11-30
Impact HIGH 8.8
CVE-2019-17403

Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.

Fix: 18a+
Fix from $1,950 2019-11-25
Spagobi HIGH 8.0
CVE-2013-6234EPSS 7%

Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by…

Fix: 4.1+
Fix from $1,950 2019-11-22
Solr CRITICAL 9.8
CVE-2019-12409EPSS 22%

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh…

No fix yet
Fix from $2,300 2019-11-18
Centraleyezer CRITICAL 9.8
CVE-2019-12271

Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded file…

No fix yet
Fix from $2,300 2019-11-18
Social Photo Gallery HIGH 7.8
CVE-2019-14467

The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover p…

No fix yet
Fix from $1,950 2019-11-18
Tipping Software CRITICAL 9.1
CVE-2019-17058

Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a whitelist can be bypassed by a…

Mitigation only
Fix from $2,300 2019-11-18
Xfilesharing CRITICAL 9.8
CVE-2019-18952EPSS 45%

SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execu…

Fix: after 2.5.1
Fix from $2,300 2019-11-13
Debian Linux HIGH 7.8
CVE-2010-4661

udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

Fix: 1.0.3+
Fix from $1,950 2019-11-13
Smart Flash Header HIGH 8.8
CVE-2014-1214

views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute ar…

Fix: after 3.0.2
Fix from $1,950 2019-11-13