Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Blackcat Cms HIGH 8.8
CVE-2017-14399

In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing…

Mitigation only
Fix from $1,950 2017-09-12
Blog CRITICAL 9.8
CVE-2017-14346

upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png…

Fix: after 2017-09-12
Fix from $2,300 2017-09-12
Nextgen Gallery HIGH 8.8
CVE-2015-9228

In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a fil…

No fix yet
Fix from $1,950 2017-09-12
TYPO3 HIGH 8.8
CVE-2017-14251

Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8…

No fix yet
Fix from $1,950 2017-09-11
Manageengine Firewall Analyzer HIGH 8.8
CVE-2017-14123EPSS 6%

Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with a…

Patch available
Fix from $1,950 2017-09-04
Blackcat Cms HIGH 8.8
CVE-2017-14050

In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .ph…

Mitigation only
Fix from $1,950 2017-08-31
Kamailio CRITICAL 9.8
CVE-2013-7426

Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.

Patch available
Fix from $2,300 2017-08-29
Sametime MEDIUM 5.5
CVE-2016-0354

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that co…

Patch available
Fix from $1,600 2017-08-29
Photo Gallery HIGH 8.8
CVE-2014-9312EPSS 45%

Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.

No fix yet
Fix from $1,950 2017-08-28
I Vu HIGH 7.8
CVE-2017-9650

An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and …

Fix: after 6.5
Fix from $1,950 2017-08-25
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2017-11357 KEVEPSS 76%

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to per…

Fix: 2020.1.114+
Fix from $2,300 2017-08-23
Experience Manager CRITICAL 9.8
CVE-2017-3108EPSS 9%

Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.

Fix: after 6.2
Fix from $2,300 2017-08-11
Photo Station HIGH 7.2
CVE-2017-11154EPSS 9%

Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to …

Fix: after 6.7.2-3429
Fix from $1,950 2017-08-08
Debian Linux HIGH 8.8
CVE-2017-12678

In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast vulnerability, which allows remote attackers to …

Patch available
Fix from $1,950 2017-08-08
Yeager Cms HIGH 7.8
CVE-2015-7571EPSS 8%

Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable e…

No fix yet
Fix from $1,950 2017-08-07
Ear Music HIGH 7.0
CVE-2017-11756

In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload exte…

Fix: after 4.1
Fix from $1,950 2017-07-30
Efront MEDIUM 6.5
CVE-2015-4462

Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary…

Fix: after 3.6.15.4
Fix from $1,600 2017-07-25
Efront MEDIUM 6.5
CVE-2015-4463

The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a…

Fix: after 3.6.15.4
Fix from $1,600 2017-07-25
Tilde Cms HIGH 7.5
CVE-2017-11326

An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipu…

No fix yet
Fix from $1,950 2017-07-24
Dotcms HIGH 7.2
CVE-2017-11466EPSS 8%

Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrato…

Patch available
Fix from $1,950 2017-07-20
Onos CRITICAL 9.8
CVE-2017-1000081

Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.

Mitigation only
Fix from $2,300 2017-07-17
A320 Firmware CRITICAL 9.8
CVE-2017-6041

An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, …

Mitigation only
Fix from $2,300 2017-06-30
Dolibarr HIGH 8.8
CVE-2017-9840

Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within t…

Fix: after 5.0.3
Fix from $1,950 2017-06-25
Avamar Server CRITICAL 9.8
CVE-2017-4990

In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of …

Mitigation only
Fix from $2,300 2017-06-21
Openemr HIGH 8.8
CVE-2017-9380EPSS 15%

OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context…

Fix: after 5.0.0
Fix from $1,950 2017-06-02
Bigtree Cms CRITICAL 9.8
CVE-2017-9364

Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety ch…

Fix: after 4.2.18
Fix from $2,300 2017-06-02
Aviary Image Editor Add On For Gravity Forms CRITICAL 9.8
CVE-2015-4455EPSS 41%

Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allow…

Fix: after 3.0
Fix from $2,300 2017-05-23
Playsms CRITICAL 9.8
CVE-2017-9101EPSS 77%

import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP co…

No fix yet
Fix from $2,300 2017-05-21
Playsms HIGH 8.8
CVE-2017-9080EPSS 62%

PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unr…

No fix yet
Fix from $1,950 2017-05-19
Web Server CRITICAL 9.8
CVE-2017-6027

An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, p…

Fix: after 2.3
Fix from $2,300 2017-05-19