Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Webiness Inventory CRITICAL 9.8
CVE-2018-18752

Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo paramete…

No fix yet
Fix from $2,300 2018-10-29
Manageengine Opmanager CRITICAL 9.8
CVE-2018-18475EPSS 20%

Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.

No fix yet
Fix from $2,300 2018-10-23
Advanced Hrm HIGH 8.8
CVE-2018-18382

Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Updat…

No fix yet
Fix from $1,950 2018-10-16
Lemon HIGH 7.5
CVE-2018-18315

com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils on…

Mitigation only
Fix from $1,950 2018-10-15
Jquery File Upload CRITICAL 9.8
CVE-2018-9206EPSS 97%

Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

Fix: after 9.22.0
Fix from $2,300 2018-10-11
Empirecms HIGH 8.8
CVE-2018-18086

EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.

No fix yet
Fix from $1,950 2018-10-09
Central Wifimanager HIGH 8.8
CVE-2018-17442EPSS 14%

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endp…

Fix: 1.03+
Fix from $1,950 2018-10-08
Central Wifimanager CRITICAL 9.8
CVE-2018-17440EPSS 38%

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and ha…

Fix: 1.03+
Fix from $2,300 2018-10-08
Video Conference CRITICAL 9.8
CVE-2015-9271

The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/v…

No fix yet
Fix from $2,300 2018-10-04
Navigate Cms HIGH 8.8
CVE-2018-17553EPSS 79%

An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authen…

Patch available
Fix from $1,950 2018-10-03
Wp Insert CRITICAL 9.8
CVE-2018-17573

The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fck…

Fix: after 2.4.2
Fix from $2,300 2018-09-28
Sitefinity HIGH 7.5
CVE-2018-17055

An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.

Fix: after 11.0
Fix from $1,950 2018-09-28
Coldfusion CRITICAL 9.8
CVE-2018-15961 KEVEPSS 100%

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnera…

Mitigation only
Fix from $2,300 2018-09-25
Seacms MEDIUM 5.3
CVE-2018-16821

SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.

No fix yet
Fix from $1,600 2018-09-21
Ultimatepos HIGH 8.8
CVE-2018-17139

UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php…

No fix yet
Fix from $1,950 2018-09-17
Supersign Cms CRITICAL 9.8
CVE-2018-16287EPSS 20%

LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.

No fix yet
Fix from $2,300 2018-09-14
Grc Suite HIGH 8.8
CVE-2018-16796

HiScout GRC Suite before 3.1.5 allows Unrestricted Upload of Files with Dangerous Types.

Fix: 3.1.5+
Fix from $1,950 2018-09-13
Elefant CRITICAL 9.8
CVE-2018-16974

An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filema…

Fix: 2.0.7+
Fix from $2,300 2018-09-12
E107 HIGH 7.2
CVE-2018-16388

e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg …

Patch available
Fix from $1,950 2018-09-12
Cscms CRITICAL 9.8
CVE-2018-16731

CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .…

No fix yet
Fix from $2,300 2018-09-08
Mtappjquery CRITICAL 9.8
CVE-2018-0645

MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors.

Fix: after 1.8.1
Fix from $2,300 2018-09-07
Limesurvey HIGH 8.8
CVE-2018-1000658

LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution…

Fix: 3.14.4+
Fix from $1,950 2018-09-06
Pescms Team CRITICAL 9.8
CVE-2018-16370

In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP…

No fix yet
Fix from $2,300 2018-09-03
Weaselcms CRITICAL 9.8
CVE-2018-16352

There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png c…

No fix yet
Fix from $2,300 2018-09-02
Joomla\! CRITICAL 9.8
CVE-2018-15882

An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the…

Fix: 3.8.12+
Fix from $2,300 2018-08-29
Umbraco Cms CRITICAL 9.8
CVE-2014-10074

Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the up…

Fix: 7.2.0+
Fix from $2,300 2018-08-27
Uptime Infrastructure Monitor CRITICAL 9.8
CVE-2015-9263EPSS 12%

An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbi…

No fix yet
Fix from $2,300 2018-08-27
Hub 2245 222 Firmware CRITICAL 9.0
CVE-2018-3832

An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows for uploading arbitrary MPFS…

Mitigation only
Fix from $2,300 2018-08-23
Librehealth Ehr HIGH 8.8
CVE-2018-1000646

LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write fi…

No fix yet
Fix from $1,950 2018-08-20
Reprise License Manager HIGH 8.8
CVE-2018-15573

An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on d…

Fix: 16.1+
Fix from $1,950 2018-08-20