Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Enterprise CRITICAL 9.8
CVE-2019-7274EPSS 29%

Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.

Fix: after 2.3.0a
Fix from $2,300 2019-07-01
Flexair HIGH 8.8
CVE-2019-7669EPSS 31%

Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated atta…

Fix: after 2.3.38
Fix from $1,950 2019-07-01
Chamilo Lms CRITICAL 9.8
CVE-2019-13082

Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive befor…

No fix yet
Fix from $2,300 2019-06-30
Seeddms HIGH 7.5
CVE-2019-12744EPSS 12%

SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-201…

Fix: 5.1.11+
Fix from $1,950 2019-06-20
Miniblog HIGH 7.2
CVE-2019-9842

madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFi…

Fix: after 2018-05-18
Fix from $1,950 2019-06-14
Alaris Gateway Workstation Firmware CRITICAL 10.0
CVE-2019-10959

BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the lat…

Fix: after 2.3.6
Fix from $2,300 2019-06-13
Coldfusion CRITICAL 9.8
CVE-2019-7838EPSS 17%

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Succ…

Mitigation only
Fix from $2,300 2019-06-12
Intelligent Operations Center HIGH 8.8
CVE-2019-4069

IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. …

Fix: after 5.2.1.1
Fix from $1,950 2019-06-07
Flexair HIGH 8.8
CVE-2019-9189EPSS 12%

Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central …

Fix: after 2.3.38
Fix from $1,950 2019-06-05
Industrial Network Director HIGH 7.2
CVE-2019-1861

A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrar…

Fix: 1.6.0+
Fix from $1,950 2019-06-05
Pydio CRITICAL 9.8
CVE-2019-9642

An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP …

Fix: after 8.2.2
Fix from $2,300 2019-06-05
Intelligent Management Center HIGH 8.8
CVE-2019-5357

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $1,950 2019-06-05
Live Chat CRITICAL 9.8
CVE-2019-11185

The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete pat…

Fix: 8.0.26+
Fix from $2,300 2019-06-03
Bludit HIGH 8.8
CVE-2019-12548

Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajax/upload…

Fix: 3.9.0+
Fix from $1,950 2019-06-03
Landesk Management Suite CRITICAL 9.8
CVE-2019-12377EPSS 6%

A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows…

No fix yet
Fix from $2,300 2019-06-03
Coldfusion CRITICAL 9.8
CVE-2019-7816EPSS 68%

ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Succes…

Mitigation only
Fix from $2,300 2019-05-24
Osclass HIGH 7.2
CVE-2016-10751

osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an …

Mitigation only
Fix from $1,950 2019-05-24
Serendipity CRITICAL 9.8
CVE-2016-10752

serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensi…

Mitigation only
Fix from $2,300 2019-05-24
Phpkit HIGH 8.8
CVE-2016-10758

PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_na…

No fix yet
Fix from $1,950 2019-05-24
Dr 250 Firmware HIGH 8.8
CVE-2018-19612

The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute…

Mitigation only
Fix from $1,950 2019-05-24
Ultimateeditor CRITICAL 9.8
CVE-2019-12150

Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The att…

No fix yet
Fix from $2,300 2019-05-24
Manageengine Opmanager MEDIUM 6.5
CVE-2017-11561

An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Ala…

No fix yet
Fix from $1,600 2019-05-23
Api Manager MEDIUM 5.4
CVE-2019-6513

An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing …

Mitigation only
Fix from $1,600 2019-05-21
Elabftw HIGH 8.8
CVE-2019-12185EPSS 18%

eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command exec…

No fix yet
Fix from $1,950 2019-05-20
Atutor HIGH 8.8
CVE-2019-12170EPSS 9%

ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote …

Fix: after 2.2.4
Fix from $1,950 2019-05-17
Simplybook CRITICAL 9.8
CVE-2019-11887

SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution.

Fix: after 2019-05-11
Fix from $2,300 2019-05-17
Php Fusion HIGH 8.8
CVE-2019-12099EPSS 18%

In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput…

Fix: 9.03.00+
Fix from $1,950 2019-05-14
Webiness Inventory MEDIUM 6.5
CVE-2019-8404EPSS 8%

An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the cre…

No fix yet
Fix from $1,600 2019-05-14
Ninja Forms File Uploads HIGH 8.1
CVE-2019-10869EPSS 8%

Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This…

Fix: 3.0.23+
Fix from $1,950 2019-05-07
Aleos HIGH 8.8
CVE-2018-4063 KEVEPSS 28%

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially craf…

Fix: 4.4.9 / 4.9.4+
Fix from $1,950 2019-05-06