Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Ofcms HIGH 8.8
CVE-2019-9608

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider…

Fix: 1.1.3+
Fix from $1,950 2019-03-06
Ofcms HIGH 8.8
CVE-2019-9609

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider…

Fix: 1.1.3+
Fix from $1,950 2019-03-06
Ofcms HIGH 8.8
CVE-2019-9612

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider…

Fix: 1.1.3+
Fix from $1,950 2019-03-06
Ofcms HIGH 7.2
CVE-2019-9613

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider…

Fix: 1.1.3+
Fix from $1,950 2019-03-06
Ofcms HIGH 8.8
CVE-2019-9617

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider…

Fix: 1.1.3+
Fix from $1,950 2019-03-06
Booked HIGH 8.8
CVE-2019-9581EPSS 13%

phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP…

Patch available
Fix from $1,950 2019-03-06
Schoolcms HIGH 7.2
CVE-2019-9572

SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with …

No fix yet
Fix from $1,950 2019-03-05
Schoolcms HIGH 7.2
CVE-2019-9181

SchoolCMS version 2.3.1 allows file upload via the logo upload feature at admin.php?m=admin&c=site&a=save by using the .jpg extension, changing the C…

No fix yet
Fix from $1,950 2019-02-26
Testrail HIGH 8.8
CVE-2018-20063

An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in t…

Mitigation only
Fix from $1,950 2019-02-25
Pluck HIGH 7.2
CVE-2019-9050

An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive…

No fix yet
Fix from $1,950 2019-02-23
Sitemagic Cms HIGH 7.2
CVE-2019-9042

An issue was discovered in Sitemagic CMS v4.4. In the index.php?SMExt=SMFiles URI, the user can upload a .php file to execute arbitrary code, as demo…

No fix yet
Fix from $1,950 2019-02-23
WordPress HIGH 8.8
CVE-2019-8942EPSS 83%

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary …

Fix: 4.9.9+
Fix from $1,950 2019-02-20
Dedecms HIGH 8.8
CVE-2019-8933

In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execu…

No fix yet
Fix from $1,950 2019-02-19
Jtbc Php HIGH 7.5
CVE-2019-8433

JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.

No fix yet
Fix from $1,950 2019-02-18
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2019-8394 KEVEPSS 63%

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

Fix: 10.0.0+
Fix from $1,600 2019-02-17
Dedecms HIGH 7.5
CVE-2019-8362

DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=sa…

Fix: 5.7+
Fix from $1,950 2019-02-16
Businessobjects CRITICAL 9.8
CVE-2019-0259

SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file for…

Mitigation only
Fix from $2,300 2019-02-15
Nc Cms HIGH 7.5
CVE-2019-7721

lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters.

No fix yet
Fix from $1,950 2019-02-11
Inxedu CRITICAL 9.8
CVE-2019-7684

inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.comm…

Fix: after 2018-12-24
Fix from $2,300 2019-02-09
User Id CRITICAL 9.8
CVE-2019-6139

Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. Successful exploitation of th…

Fix: 1.3.0+
Fix from $2,300 2019-02-07
Junos Space HIGH 8.8
CVE-2019-0017

The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of maliciou…

Mitigation only
Fix from $1,950 2019-01-15
Security Identity Manager CRITICAL 9.9
CVE-2018-1969

IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the…

Fix: after 6.0.0.20
Fix from $2,300 2019-01-14
Remote Service Manager HIGH 8.8
CVE-2018-16169

Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.

Fix: after 3.1.0
Fix from $1,950 2019-01-09
Vtiger Crm HIGH 7.2
CVE-2019-5009EPSS 10%

Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and …

Fix: after 7.1.0
Fix from $1,950 2019-01-04
Rukovoditel HIGH 8.8
CVE-2018-20166EPSS 7%

A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishan…

No fix yet
Fix from $1,950 2019-01-02
Ml Report CRITICAL 9.8
CVE-2018-5204

ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote ar…

Fix: after 2.18.628.5980
Fix from $2,300 2018-12-28
Big Ip Local Traffic Manager MEDIUM 5.5
CVE-2018-15333

On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including Guest Role, to have access an…

Fix: after 14.1.0
Fix from $1,600 2018-12-28
Iiot Monitor CRITICAL 9.8
CVE-2018-7836EPSS 32%

An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow uplo…

Mitigation only
Fix from $2,300 2018-12-24
Librehealth Ehr HIGH 8.8
CVE-2018-1000839

LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This atta…

No fix yet
Fix from $1,950 2018-12-20
Bludit HIGH 8.8
CVE-2018-1000811EPSS 48%

bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Re…

No fix yet
Fix from $1,950 2018-12-20