Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Litecart HIGH 8.8
CVE-2018-12256

admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code e…

Fix: 2.1.3+
Fix from $1,950 2018-08-16
Openemr HIGH 8.8
CVE-2018-15139EPSS 19%

Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to exe…

Fix: 5.0.1.4+
Fix from $1,950 2018-08-13
WordPress HIGH 7.2
CVE-2018-14028EPSS 15%

In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP fil…

Patch available
Fix from $1,950 2018-08-10
Clr M20 Firmware CRITICAL 9.8
CVE-2018-15137EPSS 18%

CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code ex…

No fix yet
Fix from $2,300 2018-08-08
Ocs Inventory Server HIGH 8.8
CVE-2018-14857

Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server thr…

Fix: after 2.5
Fix from $1,950 2018-08-06
Ukcms HIGH 7.2
CVE-2018-14911

A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filtering the file upload type. A…

Fix: after 1.1.7
Fix from $1,950 2018-08-03
Groupwise HIGH 7.2
CVE-2018-12468

A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an admini…

Fix: 18.0.2+
Fix from $1,950 2018-08-01
Seeddms HIGH 8.8
CVE-2018-12940

Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to ex…

Fix: 5.1.8+
Fix from $1,950 2018-07-31
Dotcms HIGH 8.1
CVE-2017-3189EPSS 7%

The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When…

Fix: after 3.7.1
Fix from $1,950 2018-07-24
B2b2c Multi Business HIGH 8.8
CVE-2018-14570

A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.11 allows any remote member to…

No fix yet
Fix from $1,950 2018-07-23
Ssh Companywebsite CRITICAL 9.8
CVE-2018-14441

An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upl…

Fix: after 2018-05-03
Fix from $2,300 2018-07-20
Joyplus Cms CRITICAL 9.8
CVE-2018-14334

manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm va…

No fix yet
Fix from $2,300 2018-07-17
Zeta Producer Desktop Cms CRITICAL 9.8
CVE-2018-13981EPSS 17%

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default co…

Fix: 14.2.1+
Fix from $2,300 2018-07-16
Php Formmail Generator CRITICAL 9.8
CVE-2016-9492

The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated…

Fix: 2016-12-17+
Fix from $2,300 2018-07-13
762 3000 Firmware HIGH 8.8
CVE-2018-12980EPSS 30%

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated use…

Fix: 02+
Fix from $1,950 2018-07-12
Ovidentia HIGH 8.8
CVE-2018-1000619

Ovidentia version 8.4.3 and earlier contains a Unsanitized User Input vulnerability in utilit.php, bab_getAddonFilePathfromTg that can result in Auth…

Fix: after 8.4.3
Fix from $1,950 2018-07-09
Powermedia Xms HIGH 7.2
CVE-2018-11638

Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated …

Fix: after 3.5
Fix from $1,950 2018-07-03
Live Chat CRITICAL 9.8
CVE-2018-12426EPSS 5%

The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation …

Fix: 8.0.07+
Fix from $2,300 2018-07-02
N150 Firmware HIGH 8.1
CVE-2018-12528

An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for importing a configuration fil…

No fix yet
Fix from $1,950 2018-07-02
Opensid CRITICAL 9.8
CVE-2018-13038

OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. This vulnerability leads to uplo…

No fix yet
Fix from $2,300 2018-07-01
Hongcms HIGH 7.2
CVE-2018-13021

An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.ph…

No fix yet
Fix from $1,950 2018-06-29
Metinfo HIGH 7.2
CVE-2018-13024

Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an…

No fix yet
Fix from $1,950 2018-06-29
Publiccms CRITICAL 9.8
CVE-2018-12914

A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a direct…

No fix yet
Fix from $2,300 2018-06-27
Debian Linux CRITICAL 9.8
CVE-2018-1000544

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary …

Fix: after 1.2.1
Fix from $2,300 2018-06-26
Shopnx HIGH 8.8
CVE-2018-12519EPSS 8%

An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js applicatio…

No fix yet
Fix from $1,950 2018-06-19
Pandora Fms CRITICAL 9.8
CVE-2018-11221EPSS 6%

Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/up…

Fix: after 7.23
Fix from $2,300 2018-06-16
Phpok CRITICAL 9.8
CVE-2018-12491

PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploadin…

No fix yet
Fix from $2,300 2018-06-15
Open Build Service CRITICAL 9.8
CVE-2011-4183

A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2…

Fix: 2.1.16+
Fix from $2,300 2018-06-13
Portfoliocms HIGH 8.8
CVE-2018-12263

portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI.

Mitigation only
Fix from $1,950 2018-06-13
Security Identity Manager HIGH 8.8
CVE-2018-1453

IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be autom…

Patch available
Fix from $1,950 2018-06-08