Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
3par Service Processor Firmware HIGH 8.8
CVE-2019-5395

A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

Fix: 5.0.5.1+
Fix from $1,950 2019-08-09
Osticket MEDIUM 5.4
CVE-2019-14748

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries.…

Fix: 1.10.7 / 1.12.1+
Fix from $1,600 2019-08-07
Magento HIGH 7.2
CVE-2019-7930

A file upload restriction bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.2
CVE-2019-7912

A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by a…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.5
CVE-2019-7861

Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento …

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.3
CVE-2017-18435

cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).

Fix: 56.0.49 / 58.0.49+
Fix from $1,950 2019-08-02
Cpanel MEDIUM 6.7
CVE-2018-20925

cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).

Fix: 62.0.42 / 68.0.33+
Fix from $1,600 2019-08-01
Cpanel MEDIUM 6.7
CVE-2018-20926

cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).

Fix: 62.0.42 / 68.0.33+
Fix from $1,600 2019-08-01
Wallacepos HIGH 7.2
CVE-2019-3960

Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a …

Patch available
Fix from $1,950 2019-07-31
Edx Platform HIGH 8.8
CVE-2015-5601

edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.

Fix: 2015-07-20+
Fix from $1,950 2019-07-29
Cloud Backup Suite HIGH 8.8
CVE-2019-10267EPSS 75%

An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any direct…

Fix: 8.1.1.50+
Fix from $1,950 2019-07-26
Gourl HIGH 7.5
CVE-2019-1010209

GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthenticated/unzuthorized Attacker can upload executabl…

Fix: after 1.4.13
Fix from $1,950 2019-07-23
Modx Revolution HIGH 7.5
CVE-2019-1010123

MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a fi…

Fix: after 2.6.4
Fix from $1,950 2019-07-23
Sp R50p Firmware CRITICAL 9.8
CVE-2019-12326

Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated …

No fix yet
Fix from $2,300 2019-07-22
Directus 7 Api HIGH 8.8
CVE-2019-13979

In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.

Fix: 2.2.1+
Fix from $1,950 2019-07-19
Directus 7 Api HIGH 8.8
CVE-2019-13980

In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote co…

Fix: after 2.3.0
Fix from $1,950 2019-07-19
Directus 7 Api HIGH 8.8
CVE-2019-13984

Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded …

Fix: 2.3.0+
Fix from $1,950 2019-07-19
Layerbb CRITICAL 9.8
CVE-2019-13973

LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.

No fix yet
Fix from $2,300 2019-07-19
Webpanel HIGH 7.5
CVE-2019-13359EPSS 26%

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp …

No fix yet
Fix from $1,950 2019-07-16
Pluckcms CRITICAL 9.8
CVE-2019-1010062

PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The component is: da…

Fix: after 4.7.4
Fix from $2,300 2019-07-16
Digsi 5 Engineering Software HIGH 7.5
CVE-2019-10930

A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication …

Mitigation only
Fix from $1,950 2019-07-11
Simatic Pcs 7 HIGH 7.2
CVE-2019-10935

A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19)…

Fix: after 7.2
Fix from $1,950 2019-07-11
Netweaver Application Server Java HIGH 7.2
CVE-2019-0327

SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.…

Mitigation only
Fix from $1,950 2019-07-10
I Onenet CRITICAL 9.8
CVE-2019-12803

In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an att…

Fix: after 4.0.16
Fix from $2,300 2019-07-10
Owasp Modsecurity Core Rule Set HIGH 7.5
CVE-2019-13464

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads ru…

Patch available
Fix from $1,950 2019-07-09
Bks Ebk Ethernet Buskoppler Pro Firmware CRITICAL 9.8
CVE-2019-12971

BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.

Fix: 3.01+
Fix from $2,300 2019-07-05
School Erp CRITICAL 9.8
CVE-2019-13294EPSS 19%

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthentic…

No fix yet
Fix from $2,300 2019-07-04
Linear Emerge Essential Firmware CRITICAL 10.0
CVE-2019-7257EPSS 70%

Linear eMerge E3-Series devices allow Unrestricted File Upload.

Fix: after 1.00-06
Fix from $2,300 2019-07-02
Linear Emerge 50p Firmware CRITICAL 10.0
CVE-2019-7268EPSS 6%

Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.

Fix: after 4.6.07
Fix from $2,300 2019-07-02
Security Guardium HIGH 8.8
CVE-2019-4292

IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the v…

Patch available
Fix from $1,950 2019-07-02