Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Schools Alert Management Script HIGH 8.8
CVE-2018-6860

Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script 2.0.2 via a profile picture.

No fix yet
Fix from $1,950 2018-02-12
Jimtawl CRITICAL 9.8
CVE-2018-6580EPSS 36%

Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.

No fix yet
Fix from $2,300 2018-02-02
Perfex Crm CRITICAL 9.8
CVE-2017-17976EPSS 13%

In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.

No fix yet
Fix from $2,300 2018-01-26
Wondercms HIGH 8.8
CVE-2017-14521EPSS 7%

In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

No fix yet
Fix from $1,950 2018-01-26
Access Manager CRITICAL 9.8
CVE-2018-1342

A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts Ne…

Mitigation only
Fix from $2,300 2018-01-26
Filehub Firmware CRITICAL 9.8
CVE-2018-5997EPSS 24%

An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, i…

No fix yet
Fix from $2,300 2018-01-25
Pxc12\/22\/36 E.d Firmware CRITICAL 9.8
CVE-2018-4834

A vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), Desigo PX…

Fix: 6.00.204+
Fix from $2,300 2018-01-24
Premium Minecraft Servers List CRITICAL 9.8
CVE-2018-5749

install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before savin…

Fix: 1.1 / 2.0.4+
Fix from $2,300 2018-01-23
Monstra HIGH 8.8
CVE-2017-18048EPSS 63%

Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase)…

Patch available
Fix from $1,950 2018-01-23
Enterprise Manager MEDIUM 6.5
CVE-2017-16594

This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build …

Mitigation only
Fix from $1,600 2018-01-23
Master Ip Camera01 Firmware CRITICAL 9.8
CVE-2018-5724EPSS 12%

MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi.

No fix yet
Fix from $2,300 2018-01-16
Webaccess HIGH 7.5
CVE-2017-16736

An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attac…

Fix: 8.3+
Fix from $1,950 2018-01-12
Ajax Upload For Gravity Forms CRITICAL 9.8
CVE-2014-4972

Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary c…

Fix: after 1.1
Fix from $2,300 2018-01-08
Avamar Server HIGH 8.8
CVE-2017-15549EPSS 6%

An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Inte…

Mitigation only
Fix from $1,950 2018-01-05
Craft Cms HIGH 8.8
CVE-2018-3814

Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option,…

No fix yet
Fix from $1,950 2018-01-01
Muslim Matrimonial Script HIGH 7.2
CVE-2017-17987

PHP Scripts Mall Muslim Matrimonial Script allows arbitrary file upload via admin/mydetails_edit.php.

No fix yet
Fix from $1,950 2017-12-30
Marketplace Digital Products Php HIGH 8.8
CVE-2017-17874EPSS 6%

Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can ma…

No fix yet
Fix from $1,950 2017-12-27
Gpweb HIGH 7.2
CVE-2017-15876

Unrestricted File Upload vulnerability in GPWeb 8.4.61 allows remote authenticated users to upload any type of file, including a PHP shell.

No fix yet
Fix from $1,950 2017-12-19
Anonymous Post Pro CRITICAL 9.8
CVE-2017-16949EPSS 19%

An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the a…

Fix: after 3.1.9
Fix from $2,300 2017-12-19
Dedecms HIGH 8.8
CVE-2017-17727

DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parame…

Fix: after 5.6
Fix from $1,950 2017-12-18
Simple Chatting System HIGH 7.5
CVE-2017-17593EPSS 6%

Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.

No fix yet
Fix from $1,950 2017-12-13
Android HIGH 7.8
CVE-2017-13156EPSS 20%

An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android I…

Patch available
Fix from $1,950 2017-12-06
Cs Cart HIGH 7.2
CVE-2017-15673

The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a …

Fix: after 4.6.2
Fix from $1,950 2017-11-28
Teampass HIGH 7.5
CVE-2017-15054

An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to R…

Fix: 2.1.27.9+
Fix from $1,950 2017-11-27
October HIGH 8.8
CVE-2017-16941

October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by dow…

Fix: after 1.0.428
Fix from $1,950 2017-11-25
Vcm5010 Firmware HIGH 8.8
CVE-2017-2737

VCM5010 with software versions earlier before V100R002C50SPC100 has an arbitrary file upload vulnerability. The software does not validate the files …

Mitigation only
Fix from $1,950 2017-11-22
Honor 7 Firmware HIGH 7.8
CVE-2017-2699

The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a pr…

Mitigation only
Fix from $1,950 2017-11-22
3960hd Firmware CRITICAL 9.8
CVE-2017-8862

The webupgrade function on the Cohu 3960HD does not verify the firmware upgrade files or process, allowing an attacker to upload a specially crafted …

Mitigation only
Fix from $2,300 2017-11-22
Invoiceplane HIGH 8.8
CVE-2017-1000238

InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver.…

No fix yet
Fix from $1,950 2017-11-17
October CRITICAL 9.8
CVE-2017-1000194

October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly othe…

Fix: after 1.0.412
Fix from $2,300 2017-11-17