Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Dedecms CRITICAL 9.8
CVE-2018-10375

A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and exe…

Mitigation only
Fix from $2,300 2018-04-25
Management Console HIGH 8.8
CVE-2018-10173EPSS 5%

Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality.

No fix yet
Fix from $1,950 2018-04-20
Z Blogphp HIGH 7.2
CVE-2018-9153

The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppC…

Mitigation only
Fix from $1,950 2018-04-16
Advanced Secure Gateway MEDIUM 6.8
CVE-2016-10258

Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administr…

Fix: 6.5.10.8 / 6.6.5.14+
Fix from $1,600 2018-04-11
Monstra HIGH 8.8
CVE-2018-9037

Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php file…

No fix yet
Fix from $1,950 2018-04-10
Disclosure Management CRITICAL 9.8
CVE-2018-2404

SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.

Mitigation only
Fix from $2,300 2018-04-10
P1354 Firmware HIGH 7.5
CVE-2018-9156

An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify the file type, and an attacke…

No fix yet
Fix from $1,950 2018-04-01
M1033 W Firmware HIGH 7.5
CVE-2018-9157

An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attac…

Mitigation only
Fix from $1,950 2018-04-01
Notary CRITICAL 9.8
CVE-2015-9259

In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating tha…

Fix: 0.1+
Fix from $2,300 2018-03-31
Phpok CRITICAL 9.8
CVE-2018-8944

PHPOK 4.8.338 has an arbitrary file upload vulnerability.

No fix yet
Fix from $2,300 2018-03-22
Photo Station HIGH 8.8
CVE-2017-16772

Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote…

Fix: 6.3-2971 / 6.8.3-3463+
Fix from $1,950 2018-03-22
Frog Cms CRITICAL 9.8
CVE-2014-4912EPSS 8%

An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.

No fix yet
Fix from $2,300 2018-03-22
Joyplus Cms CRITICAL 9.8
CVE-2018-8766

joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.p…

No fix yet
Fix from $2,300 2018-03-18
St14.2 HIGH 8.8
CVE-2017-16251

A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious scr…

Mitigation only
Fix from $1,950 2018-03-13
Cms Made Simple HIGH 7.2
CVE-2018-1000094EPSS 39%

CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that ha…

No fix yet
Fix from $1,950 2018-03-13
Glpi HIGH 7.5
CVE-2018-7562

A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable …

Fix: after 9.2.1
Fix from $1,950 2018-03-12
Web Management Portal CRITICAL 9.8
CVE-2014-2592

Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code by uploading a file with an e…

Mitigation only
Fix from $2,300 2018-03-09
Emc Solutions Enabler Virtual Appliance HIGH 8.8
CVE-2018-1215

An arbitrary file upload vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, D…

Fix: 8.4.0.18 / 8.4.0.21+
Fix from $1,950 2018-03-08
Exponent Cms CRITICAL 9.8
CVE-2016-7443

Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."

Fix: after 2.3.9
Fix from $2,300 2018-03-07
Clipbucket CRITICAL 9.8
CVE-2018-7665EPSS 16%

An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.ph…

Fix: after 4.0.0
Fix from $2,300 2018-03-05
Otrs HIGH 7.2
CVE-2018-7567EPSS 5%

In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to expl…

Fix: after 5.0.23
Fix from $1,950 2018-03-04
Open Buildservice HIGH 7.8
CVE-2015-0796

In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files l…

Fix: 2.4.8 / 2.5.7+
Fix from $1,950 2018-03-02
Edirectory HIGH 8.8
CVE-2017-7429

The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authen…

Fix: after 8.8.8
Fix from $1,950 2018-03-02
Identity Manager HIGH 7.2
CVE-2017-9279

NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Applicat…

Fix: 4.5.6.1+
Fix from $1,950 2018-03-02
Drupal MEDIUM 6.5
CVE-2017-6931

In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not…

Fix: 8.4.5+
Fix from $1,600 2018-03-01
Proclaim CRITICAL 9.8
CVE-2018-7316EPSS 8%

Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.

No fix yet
Fix from $2,300 2018-02-22
Bravo Solution HIGH 8.8
CVE-2018-7217

In Bravo Tejari Procurement Portal, uploaded files are not properly validated by the application either on the client or the server side. An attacker…

No fix yet
Fix from $1,950 2018-02-18
Version Control Repository Manager HIGH 8.8
CVE-2016-8515

A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.…

Fix: 7.6+
Fix from $1,950 2018-02-15
Maximo Asset Management HIGH 8.8
CVE-2017-1499

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary…

Patch available
Fix from $1,950 2018-02-14
Struxureon Gateway HIGH 7.2
CVE-2017-9970

A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains care…

Fix: after 1.1.3
Fix from $1,950 2018-02-12