Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Users Ultra Membership HIGH 8.8
CVE-2015-9402

The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.

Fix: 1.5.59+
Fix from $1,950 2019-09-20
Adas MEDIUM 6.5
CVE-2019-14916

An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file upload.

No fix yet
Fix from $1,600 2019-09-20
Publisure HIGH 7.2
CVE-2019-14252

An issue was discovered in the secure portal in Publisure 2.1.2. Once successfully authenticated as an administrator, one is able to inject arbitrary…

No fix yet
Fix from $1,950 2019-09-18
Xiaomi Millet Firmware HIGH 7.4
CVE-2019-15843

A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition involving a man-in-the-middle a…

Mitigation only
Fix from $1,950 2019-09-18
Telvolution CRITICAL 9.8
CVE-2016-10995

The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.

Fix: 2.3.0+
Fix from $2,300 2019-09-18
Meg6501 0001 Firmware HIGH 8.8
CVE-2019-6839

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 …

Fix: 1.3.7+
Fix from $1,950 2019-09-17
Code42 CRITICAL 9.8
CVE-2019-15131

In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploa…

Fix: after 6.8.8
Fix from $2,300 2019-09-17
Openemr HIGH 7.2
CVE-2019-8371

OpenEMR v5.0.1-6 allows code execution.

No fix yet
Fix from $1,950 2019-09-16
Estatik HIGH 7.5
CVE-2016-10958

The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php.

Fix: 2.3.0+
Fix from $1,950 2019-09-16
Estatik MEDIUM 6.5
CVE-2016-10959

The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin…

Fix: 2.3.1+
Fix from $1,600 2019-09-16
Pimcore HIGH 8.8
CVE-2019-16318

In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by …

Fix: 5.7.1+
Fix from $1,950 2019-09-14
Neosense CRITICAL 9.8
CVE-2016-10954

The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.

Fix: 1.8+
Fix from $2,300 2019-09-13
Cysteme Finder CRITICAL 9.8
CVE-2016-10955

The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.

Fix: 1.4+
Fix from $2,300 2019-09-13
Doccms CRITICAL 9.8
CVE-2019-16192

upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module …

No fix yet
Fix from $2,300 2019-09-09
Oklite HIGH 8.8
CVE-2019-16131EPSS 7%

framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be writte…

No fix yet
Fix from $1,950 2019-09-09
Rich Text Formatter CRITICAL 9.8
CVE-2019-13187

The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fi…

Fix: after 1.1.1
Fix from $2,300 2019-09-05
Chat CRITICAL 9.8
CVE-2019-13976

eGain Chat 15.0.3 allows unrestricted file upload.

Mitigation only
Fix from $2,300 2019-09-04
Sentrifugo HIGH 8.8
CVE-2019-15813EPSS 33%

Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell.

No fix yet
Fix from $1,950 2019-09-04
Crelly Slider HIGH 8.8
CVE-2019-15866

The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_ajax_crellyslider_importSlide…

Fix: 1.3.5+
Fix from $1,950 2019-09-03
Wc Catalog Enquiry HIGH 7.5
CVE-2017-18592

The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.

Fix: 3.1.0+
Fix from $1,950 2019-08-27
Insert Or Embed Articulate Content HIGH 8.8
CVE-2019-15649

The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.

Fix: 4.2999+
Fix from $1,950 2019-08-27
Csz Cms CRITICAL 9.8
CVE-2019-15524

CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote …

Mitigation only
Fix from $2,300 2019-08-26
Wordpress File Upload HIGH 7.5
CVE-2015-9338

The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.

Fix: 2.5.0+
Fix from $1,950 2019-08-22
Wordpress File Upload HIGH 7.5
CVE-2015-9339

The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.

Fix: 2.7.1+
Fix from $1,950 2019-08-22
Wordpress File Upload HIGH 7.5
CVE-2015-9340

The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and…

Fix: 3.0.0+
Fix from $1,950 2019-08-22
Wordpress File Upload HIGH 7.5
CVE-2015-9341

The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.

Fix: 3.4.1+
Fix from $1,950 2019-08-22
Mirasys Vms CRITICAL 9.8
CVE-2019-11031

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload fil…

Fix: 7.6.1 / 8.3.2+
Fix from $2,300 2019-08-22
Oscommerce HIGH 7.2
CVE-2018-18572

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP…

Mitigation only
Fix from $1,950 2019-08-22
Integria Ims CRITICAL 9.8
CVE-2019-15091

filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.

Mitigation only
Fix from $2,300 2019-08-16
Leaf Admin HIGH 8.8
CVE-2019-14755

The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type.

Mitigation only
Fix from $1,950 2019-08-15