Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Web Viewer HIGH 8.8
CVE-2017-16524EPSS 30%

Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote auth…

No fix yet
Fix from $1,950 2017-11-06
Triton Datacenter HIGH 8.8
CVE-2017-10940EPSS 5%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to [email protected].…

Mitigation only
Fix from $1,950 2017-10-31
Phpinventory CRITICAL 9.8
CVE-2017-15990EPSS 8%

Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.

No fix yet
Fix from $2,300 2017-10-31
Ingenious School Management System HIGH 8.8
CVE-2017-15957

my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.

No fix yet
Fix from $1,950 2017-10-29
Istock Management System CRITICAL 9.8
CVE-2017-15962

iStock Management System 1.0 allows Arbitrary File Upload via user/profile.

No fix yet
Fix from $2,300 2017-10-29
Labwiki HIGH 8.8
CVE-2011-4334EPSS 6%

edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP fil…

Fix: after 1.1
Fix from $1,950 2017-10-23
Osticket CRITICAL 9.8
CVE-2017-15580EPSS 16%

osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's c…

No fix yet
Fix from $2,300 2017-10-23
X2crm HIGH 8.8
CVE-2014-2664

Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in X2Engine …

Fix: after 3.7.5
Fix from $1,950 2017-10-17
Berta Cms CRITICAL 9.8
CVE-2015-2780EPSS 15%

Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an execu…

Fix: after 0.8.9b
Fix from $2,300 2017-10-16
October HIGH 7.2
CVE-2017-1000119EPSS 61%

October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applicatio…

No fix yet
Fix from $1,950 2017-10-05
Tomcat HIGH 8.1
CVE-2017-12617 KEVEPSS 100%

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett…

Fix: 7.0.82 / 8.0.47+
Fix from $1,950 2017-10-04
Phpcollab HIGH 8.8
CVE-2017-6090EPSS 96%

Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrar…

Fix: after 2.5.1
Fix from $1,950 2017-10-03
Pivotx HIGH 7.2
CVE-2017-14958

lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload…

Patch available
Fix from $1,950 2017-10-02
Bsm Platform Application Performance Management System Health HIGH 8.8
CVE-2017-13982

A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows…

Mitigation only
Fix from $1,950 2017-09-30
Job Links HIGH 8.8
CVE-2017-14838

TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.

No fix yet
Fix from $1,950 2017-09-28
Photo Fusion HIGH 8.8
CVE-2017-14839

TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.

No fix yet
Fix from $1,950 2017-09-28
Ticketplus HIGH 8.8
CVE-2017-14840

TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.

No fix yet
Fix from $1,950 2017-09-28
Annual Maintenance Contract Management System MEDIUM 6.5
CVE-2017-14841

Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.

No fix yet
Fix from $1,600 2017-09-28
Desktop Central CRITICAL 9.8
CVE-2015-8249EPSS 74%

The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via th…

Patch available
Fix from $2,300 2017-09-28
Airbnb Clone HIGH 8.8
CVE-2017-14704EPSS 8%

Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow rem…

No fix yet
Fix from $1,950 2017-09-26
Mobile Security HIGH 8.8
CVE-2017-14079EPSS 11%

Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on…

Patch available
Fix from $1,950 2017-09-22
Dlx Spot Player4 HIGH 8.8
CVE-2017-12929EPSS 10%

Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files lea…

No fix yet
Fix from $1,950 2017-09-21
Netsweeper HIGH 7.2
CVE-2014-9619EPSS 7%

Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x bef…

Fix: after 3.1.9
Fix from $1,950 2017-09-19
Tomcat HIGH 8.1
CVE-2017-12615 KEVEPSS 100%

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t…

Fix: after 7.0.79
Fix from $1,950 2017-09-19
Mobile Friendly App Builder By Easytouch CRITICAL 9.8
CVE-2017-1002000EPSS 27%

Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/i…

No fix yet
Fix from $2,300 2017-09-14
Mobile App Builder By Wappress CRITICAL 9.8
CVE-2017-1002001EPSS 11%

Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedi…

No fix yet
Fix from $2,300 2017-09-14
Webapp Builder CRITICAL 9.8
CVE-2017-1002002EPSS 13%

Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/

No fix yet
Fix from $2,300 2017-09-14
Wp2android Turn Wp Site Into Android App CRITICAL 9.8
CVE-2017-1002003EPSS 12%

Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http:/…

No fix yet
Fix from $2,300 2017-09-14
Membership Simplified CRITICAL 9.8
CVE-2017-1002008EPSS 17%

Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-memb…

No fix yet
Fix from $2,300 2017-09-14
Flickr Picture Backup CRITICAL 9.8
CVE-2017-1002016

Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticat…

No fix yet
Fix from $2,300 2017-09-14