Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Schools Alert Management Script CRITICAL 9.8
CVE-2018-12051

Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as …

No fix yet
Fix from $2,300 2018-06-08
Dedecms CRITICAL 9.8
CVE-2018-12045

DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfi…

Fix: 5.7+
Fix from $2,300 2018-06-08
Express Cart HIGH 8.8
CVE-2018-3758EPSS 27%

Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.

Fix: 1.1.7+
Fix from $1,950 2018-06-07
Cf Deployment HIGH 7.2
CVE-2018-1265

Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF a…

Fix: 1.37.0 / 2.8.0+
Fix from $1,950 2018-06-06
Pluck CRITICAL 9.8
CVE-2018-11736EPSS 9%

An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using th…

Fix: after 4.7.7
Fix from $2,300 2018-06-05
Mahara HIGH 7.5
CVE-2018-11196

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files int…

Fix: 17.04.8 / 17.10.5+
Fix from $1,950 2018-06-01
Php Login \& User Management HIGH 8.8
CVE-2018-11392

An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the En…

Fix: 4.1.1+
Fix from $1,950 2018-05-29
Nvrmini 2 Firmware CRITICAL 9.8
CVE-2018-11523EPSS 10%

upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.

Fix: after 3.6.5
Fix from $2,300 2018-05-29
Naukri Clone Script HIGH 8.8
CVE-2018-11514

PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated…

Fix: after 3.0.3
Fix from $1,950 2018-05-28
Machform CRITICAL 9.8
CVE-2018-6411EPSS 6%

An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to …

No fix yet
Fix from $2,300 2018-05-26
Opencart HIGH 8.0
CVE-2018-11494

The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows att…

Fix: after 3.0.2.0
Fix from $1,950 2018-05-26
Xenmobile Server CRITICAL 9.8
CVE-2018-10648

There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

Mitigation only
Fix from $2,300 2018-05-23
Hawtio HIGH 7.8
CVE-2017-2617

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file…

Fix: 1.5.5+
Fix from $1,950 2018-05-22
Joomla\! HIGH 7.5
CVE-2018-11322

An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by…

Fix: 3.8.8+
Fix from $1,950 2018-05-22
As6202t Firmware HIGH 7.2
CVE-2018-11340

An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified…

No fix yet
Fix from $1,950 2018-05-22
As6202t Firmware HIGH 8.8
CVE-2018-11345

An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST param…

No fix yet
Fix from $1,950 2018-05-22
Pluck CRITICAL 9.8
CVE-2018-11331

An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing s…

Fix: 4.7.6+
Fix from $2,300 2018-05-21
Connect MEDIUM 6.1
CVE-2018-4921

Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerability. Successful exploitation could lead to informat…

Fix: after 9.7
Fix from $1,600 2018-05-19
Projectpier HIGH 8.8
CVE-2018-10760

Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP…

Fix: after 0.8.8
Fix from $1,950 2018-05-16
Webaccess CRITICAL 9.8
CVE-2018-7505

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $2,300 2018-05-15
Frog Cms HIGH 7.2
CVE-2018-11098

An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CV…

No fix yet
Fix from $1,950 2018-05-15
Myprocurenet CRITICAL 9.9
CVE-2018-11091

An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker…

No fix yet
Fix from $2,300 2018-05-14
Joruri Gw HIGH 8.8
CVE-2018-0568

Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver 3.2.0 and earlier allows remote authenticated users to execute arbitrary PHP …

Fix: after 3.2.0
Fix from $1,950 2018-05-14
Attribute Wizard CRITICAL 9.8
CVE-2018-10942EPSS 13%

modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to exe…

No fix yet
Fix from $2,300 2018-05-10
Internet Graphics Server CRITICAL 9.8
CVE-2018-2420

SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper fi…

Mitigation only
Fix from $2,300 2018-05-09
Liferay Portal HIGH 8.8
CVE-2018-10795

Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatica…

Fix: after 6.2.5
Fix from $1,950 2018-05-07
Prime Data Center Network Manager CRITICAL 9.8
CVE-2018-0258EPSS 49%

A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to a…

Mitigation only
Fix from $2,300 2018-05-02
Ap200 Firmware HIGH 8.8
CVE-2018-10577EPSS 7%

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.…

Fix: 1.2.9.15 / 2.0.0.10+
Fix from $1,950 2018-05-02
Artifactory CRITICAL 9.8
CVE-2016-10036EPSS 26%

Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary serv…

Fix: 4.16+
Fix from $2,300 2018-05-01
Symphony CRITICAL 9.8
CVE-2018-10469

b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.

No fix yet
Fix from $2,300 2018-04-27