Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Woocommerce Checkout Manager HIGH 7.5
CVE-2019-11807

The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm …

Fix: 4.3+
Fix from $1,950 2019-05-06
Doorgets Cms HIGH 8.8
CVE-2019-11615

/fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upl…

No fix yet
Fix from $1,950 2019-04-30
Aikcms HIGH 8.8
CVE-2019-11568

An issue was discovered in AikCms v2.0. There is a File upload vulnerability, as demonstrated by an admin/page/system/nav.php request with PHP code i…

No fix yet
Fix from $1,950 2019-04-27
Activematrix Bpm HIGH 8.8
CVE-2019-8992

The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIB…

Fix: after 4.2.0
Fix from $1,950 2019-04-24
My Cloud Mirror Gen 2 Firmware CRITICAL 9.8
CVE-2019-9951

Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR21…

Fix: 2.31.174+
Fix from $2,300 2019-04-24
Atutor HIGH 8.8
CVE-2019-11446EPSS 8%

An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files s…

Fix: after 2.2.4
Fix from $1,950 2019-04-22
Cutenews HIGH 8.8
CVE-2019-11447EPSS 52%

An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via th…

No fix yet
Fix from $1,950 2019-04-22
Openkm HIGH 7.2
CVE-2019-11445EPSS 14%

OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory …

Fix: 6.3.7+
Fix from $1,950 2019-04-22
Siteserver Cms HIGH 7.2
CVE-2019-11401

A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted f…

No fix yet
Fix from $1,950 2019-04-22
Wcms HIGH 8.8
CVE-2019-11377

wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according …

No fix yet
Fix from $1,950 2019-04-20
Pluck CRITICAL 9.8
CVE-2019-11344

data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-p…

No fix yet
Fix from $2,300 2019-04-19
Supportcandy CRITICAL 9.8
CVE-2019-11223EPSS 9%

An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by…

Fix: after 2.0.0
Fix from $2,300 2019-04-18
Xperience HIGH 8.8
CVE-2018-19453

Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.

Fix: 11.0.45+
Fix from $1,950 2019-04-10
Bigfix Platform CRITICAL 9.9
CVE-2019-4013EPSS 14%

IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in cod…

Fix: after 9.5.11
Fix from $2,300 2019-04-10
Webaccess CRITICAL 9.8
CVE-2019-3940

Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnera…

Mitigation only
Fix from $2,300 2019-04-09
Web Module HIGH 8.8
CVE-2019-11028

GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to the server via the "Document…

Fix: 1.40+
Fix from $1,950 2019-04-09
Rbw 100 Firmware HIGH 7.2
CVE-2019-10478

An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. An unrestricted file upload vulnerability in the Front Circle Contro…

No fix yet
Fix from $1,950 2019-04-05
Content Manager HIGH 7.5
CVE-2019-3489

An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when co…

Fix: after 9.3
Fix from $1,950 2019-04-01
Flatcore HIGH 7.2
CVE-2019-10652EPSS 7%

An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addo…

No fix yet
Fix from $1,950 2019-03-30
Zzzphp CRITICAL 9.8
CVE-2019-10647EPSS 7%

ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage…

No fix yet
Fix from $2,300 2019-03-30
Razor CRITICAL 9.8
CVE-2019-10276

Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the im…

No fix yet
Fix from $2,300 2019-03-29
Internet Campus Solution HIGH 7.5
CVE-2019-10012

Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archi…

Fix: 2.1.4+
Fix from $1,950 2019-03-25
Unibox Firmware HIGH 8.8
CVE-2019-3495

An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, all…

No fix yet
Fix from $1,950 2019-03-21
Roxy Fileman CRITICAL 9.8
CVE-2018-20526EPSS 73%

Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.

No fix yet
Fix from $2,300 2019-03-21
Webgalamb CRITICAL 9.8
CVE-2018-19514

In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authent…

Fix: after 7.0
Fix from $2,300 2019-03-21
Feifeicms CRITICAL 9.8
CVE-2019-9825

FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowa…

Mitigation only
Fix from $2,300 2019-03-14
Cms Made Simple MEDIUM 6.5
CVE-2019-9692EPSS 46%

class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JP…

Fix: 2.2.10+
Fix from $1,600 2019-03-11
Bolt HIGH 8.8
CVE-2019-9185

Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a pr…

Fix: 3.6.5+
Fix from $1,950 2019-03-07
Monstra HIGH 7.2
CVE-2018-17418

Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, bec…

No fix yet
Fix from $1,950 2019-03-07
Feng Office CRITICAL 9.8
CVE-2019-9623EPSS 8%

Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.

No fix yet
Fix from $2,300 2019-03-07