Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Symfony MEDIUM 5.3
CVE-2018-19789

An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x be…

Fix: 2.7.50 / 2.8.49+
Fix from $1,600 2018-12-18
Chrome CRITICAL 9.6
CVE-2018-6152

The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome pri…

Fix: 66.0.3359.106+
Fix from $2,300 2018-12-04
Xclarity Integrator MEDIUM 6.5
CVE-2018-16093

In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload…

Fix: 5.5+
Fix from $1,600 2018-11-30
Xclarity Integrator MEDIUM 6.5
CVE-2018-16097

LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system …

Fix: 3.5 / 5.5+
Fix from $1,600 2018-11-30
Ocsinventory Ng HIGH 8.8
CVE-2018-15537EPSS 5%

Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain access to the server via crafte…

No fix yet
Fix from $1,950 2018-11-29
Tp5cms CRITICAL 9.8
CVE-2018-19692

An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploadin…

Fix: after 2017-05-25
Fix from $2,300 2018-11-29
Nuuo Cms CRITICAL 9.8
CVE-2018-17936EPSS 15%

NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the serv…

Fix: after 3.3
Fix from $2,300 2018-11-27
Phpok HIGH 8.8
CVE-2018-19562

An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Prog…

No fix yet
Fix from $1,950 2018-11-26
Email Marketer HIGH 8.8
CVE-2018-19550EPSS 6%

Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can …

Fix: after 6.1.6
Fix from $1,950 2018-11-26
Archer C5 Firmware HIGH 7.2
CVE-2018-19537EPSS 6%

TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuratio…

Fix: after 2_160201_us
Fix from $1,950 2018-11-26
Faq Script HIGH 7.2
CVE-2018-19457

Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faqimages with a .php file.

No fix yet
Fix from $1,950 2018-11-22
Subrion Cms HIGH 7.2
CVE-2018-19422EPSS 64%

/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits …

No fix yet
Fix from $1,950 2018-11-21
Codiad HIGH 7.2
CVE-2018-19423EPSS 18%

Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.

No fix yet
Fix from $1,950 2018-11-21
Clippercms HIGH 7.2
CVE-2018-19424

ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.

Mitigation only
Fix from $1,950 2018-11-21
Accu Chek Inform Ii Firmware CRITICAL 9.6
CVE-2018-18563

An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number a…

Fix: 03.01.03 / 03.01.06+
Fix from $2,300 2018-11-20
Accu Chek Inform Ii Firmware MEDIUM 6.8
CVE-2018-18565

An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number a…

Fix: 03.01.03 / 03.01.06+
Fix from $1,600 2018-11-20
Php Traditional Server CRITICAL 9.8
CVE-2018-9209

Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2

Fix: after 1.2.2
Fix from $2,300 2018-11-19
Jquery Upload File CRITICAL 9.8
CVE-2018-9207

Arbitrary file upload in jQuery Upload File <= 4.0.2

Fix: after 4.0.2
Fix from $2,300 2018-11-19
Prestashop CRITICAL 9.8
CVE-2018-19355

modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute …

Fix: after 1.7.0.0
Fix from $2,300 2018-11-19
School Event Management System CRITICAL 9.8
CVE-2018-18793EPSS 10%

School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.

No fix yet
Fix from $2,300 2018-11-16
Debun Imap HIGH 8.8
CVE-2018-0686

Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers…

Fix: after 3.3p_r4.0
Fix from $1,950 2018-11-15
Prestashop CRITICAL 9.8
CVE-2018-19126EPSS 23%

PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.

Fix: 1.6.1.23 / 1.7.4.4+
Fix from $2,300 2018-11-09
Jquery Picture Cut CRITICAL 9.8
CVE-2018-9208

Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta

No fix yet
Fix from $2,300 2018-11-05
Popojicms CRITICAL 9.8
CVE-2018-18934

An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the …

No fix yet
Fix from $2,300 2018-11-05
Basercms HIGH 7.2
CVE-2018-18942

In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data…

Fix: 4.1.4+
Fix from $1,950 2018-11-05
Robotic Process Automation With Automation Anywhere HIGH 8.8
CVE-2018-1552

IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a m…

Patch available
Fix from $1,950 2018-11-02
Laravelcms CRITICAL 9.8
CVE-2018-18888

An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files be…

Fix: after 2018-04-02
Fix from $2,300 2018-11-01
Nc Cms CRITICAL 9.8
CVE-2018-18874

nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Con…

Fix: after 2017-03-10
Fix from $2,300 2018-10-31
Mcms CRITICAL 9.8
CVE-2018-18830

An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login sta…

Mitigation only
Fix from $2,300 2018-10-30
Lulu Cms HIGH 7.5
CVE-2018-18771

An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by…

Fix: after 2015-05-14
Fix from $1,950 2018-10-29