Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Sharepoint Enterprise Server MEDIUM 6.5
CVE-2019-1443EPSS 5%

An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An …

Patch available
Fix from $1,600 2019-11-12
Sunveillance Monitoring System \& Data Recorder CRITICAL 9.8
CVE-2019-12719

An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnera…

Fix: 1.1.9e+
Fix from $2,300 2019-11-12
Magento HIGH 7.2
CVE-2019-8114

A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2…

Fix: 1.9.4.3 / 1.14.4.3+
Fix from $1,950 2019-11-05
Magento HIGH 8.8
CVE-2019-8093

An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can lever…

Fix: 2.2.10 / 2.3.2+
Fix from $1,950 2019-11-05
Serendipity CRITICAL 9.8
CVE-2011-1134

Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the im…

Fix: 1.5.5+
Fix from $2,300 2019-11-05
TYPO3 HIGH 8.8
CVE-2010-3663

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPatter…

Fix: 4.1.14 / 4.2.13+
Fix from $1,950 2019-11-04
Rexpert MEDIUM 6.5
CVE-2019-17325

ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. T…

Fix: after 1.0.0.527
Fix from $1,600 2019-10-30
Infobusiness HIGH 8.8
CVE-2019-18204

Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.

Fix: after 4.4.1
Fix from $1,950 2019-10-30
Carousel Digital Signage HIGH 8.8
CVE-2018-18930

The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature…

Fix: after 7.0.4.104
Fix from $1,950 2019-10-29
Repetier Server CRITICAL 9.8
CVE-2019-14451

RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when uploading a new printer config…

Fix: after 0.91
Fix from $2,300 2019-10-25
Restaurant Management System HIGH 8.8
CVE-2019-18417

Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The iss…

No fix yet
Fix from $1,950 2019-10-24
Cms HIGH 7.2
CVE-2019-11021

admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE: "While inadverten…

Mitigation only
Fix from $1,950 2019-10-24
Showbiz Pro CRITICAL 9.8
CVE-2015-9499EPSS 16%

The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

Fix: after 1.7.1
Fix from $2,300 2019-10-22
Nexus Iq Server HIGH 7.2
CVE-2019-16530

Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.

Fix: after 72
Fix from $1,950 2019-10-21
Slub Events CRITICAL 9.8
CVE-2019-16700

The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1…

Fix: after 3.0.2
Fix from $2,300 2019-10-16
Jiangnan Online Judge HIGH 8.8
CVE-2019-17490

app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by PHP code…

No fix yet
Fix from $1,950 2019-10-10
Acf Fronted Display CRITICAL 9.8
CVE-2015-9479

The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upl…

Fix: after 2015-07-03
Fix from $2,300 2019-10-10
Zoomsounds CRITICAL 9.8
CVE-2015-9471

The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.

Fix: after 2.0
Fix from $2,300 2019-10-10
Centreon CRITICAL 9.8
CVE-2018-21024

licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.

Fix: 2.8.27+
Fix from $2,300 2019-10-08
Vp59 Firmware HIGH 8.8
CVE-2019-14656

Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user)…

Fix: after 2019-08-04
Fix from $1,950 2019-10-08
Vp59 Firmware HIGH 8.8
CVE-2019-14657

Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extracti…

Fix: after 2019-08-04
Fix from $1,950 2019-10-08
Jfinal HIGH 7.5
CVE-2019-17352

In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type o…

Fix: 4.4+
Fix from $1,950 2019-10-08
Sitos Six CRITICAL 9.8
CVE-2019-15748

SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticate…

Mitigation only
Fix from $2,300 2019-10-07
Sitos Six CRITICAL 9.8
CVE-2019-15751

An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with …

Mitigation only
Fix from $2,300 2019-10-07
Fecmall HIGH 7.2
CVE-2019-17188

An unrestricted file upload vulnerability was discovered in catalog/productinfo/imageupload in Fecshop FecMall 2.3.4. An attacker can bypass a front-…

No fix yet
Fix from $1,950 2019-10-04
Arcsight Logger HIGH 8.8
CVE-2019-11655

Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of…

Mitigation only
Fix from $1,950 2019-10-04
Ksweb HIGH 8.8
CVE-2019-15766

The KSLABS KSWEB (aka ru.kslabs.ksweb) application 3.93 for Android allows authenticated remote code execution via a POST request to the AJAX handler…

No fix yet
Fix from $1,950 2019-10-03
Ilch Cms HIGH 7.2
CVE-2019-17046

Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page.

No fix yet
Fix from $1,950 2019-09-30
Ckfinder HIGH 7.5
CVE-2019-15862

An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (eve…

Fix: 2.6.3+
Fix from $1,950 2019-09-26
Zzzphp HIGH 7.5
CVE-2019-16720

ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by…

No fix yet
Fix from $1,950 2019-09-23