Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Modx Revolution HIGH 8.8
CVE-2017-9069

In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.

Fix: after 2.5.6
Fix from $1,950 2017-05-18
Hipchat Server HIGH 8.8
CVE-2017-8080

Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving im…

Fix: after 2.2.3
Fix from $1,950 2017-05-05
Joomla\! MEDIUM 6.5
CVE-2017-7989

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explic…

Patch available
Fix from $1,600 2017-04-25
Hipchat Server CRITICAL 9.1
CVE-2017-7357

Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a fil…

Fix: after 2.2.2
Fix from $2,300 2017-04-14
Vtiger Crm HIGH 7.3
CVE-2016-1713EPSS 17%

Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.p…

No fix yet
Fix from $1,950 2017-04-14
Enterprise Backup HIGH 8.8
CVE-2017-7281

An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport func…

Fix: after 9.1.1
Fix from $1,950 2017-04-12
Bigtree Cms CRITICAL 9.8
CVE-2017-7695

Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and e…

Fix: after 4.2.16
Fix from $2,300 2017-04-11
Qdpm HIGH 8.8
CVE-2015-3884EPSS 14%

Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pa…

Fix: after 9.1
Fix from $1,950 2017-03-17
Zen Mobile App Native HIGH 7.5
CVE-2017-6104EPSS 7%

Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.

Fix: after 3.0
Fix from $1,950 2017-03-02
Security Key Lifecycle Manager HIGH 7.2
CVE-2016-6104

IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file exte…

Patch available
Fix from $1,950 2017-02-07
Kenexa Lms On Cloud HIGH 8.8
CVE-2016-6124

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arb…

Mitigation only
Fix from $1,950 2017-02-01
Filenet Workplace Xt HIGH 8.8
CVE-2016-8921

IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vul…

Mitigation only
Fix from $1,950 2017-02-01
Genixcms HIGH 8.8
CVE-2017-5520

The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, wh…

Fix: after 0.0.8
Fix from $1,950 2017-01-17
Dotclear HIGH 8.8
CVE-2016-7902

Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to…

Fix: after 2.10.2
Fix from $1,950 2017-01-04
Dotclear HIGH 7.2
CVE-2016-9268EPSS 5%

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote au…

Fix: after 2.10.4
Fix from $1,950 2016-11-10
Moodle HIGH 8.8
CVE-2016-9187

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to exe…

Fix: after 3.1.2
Fix from $1,950 2016-11-04
Moodle HIGH 8.8
CVE-2016-9186

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to e…

Fix: after 3.1.2
Fix from $1,950 2016-11-04
Exponent Cms HIGH 7.5
CVE-2016-7452

The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder on the site via a cpi directo…

Fix: after 2.3.9
Fix from $1,950 2016-11-03
Exponent Cms CRITICAL 9.8
CVE-2016-7095

Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected fold…

Fix: after 2.3.8
Fix from $2,300 2016-11-03
Csv2wpec Coupon HIGH 7.8
CVE-2015-1000013

Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1

No fix yet
Fix from $1,950 2016-10-06
Fast Image Adder CRITICAL 9.8
CVE-2015-1000001

Remote file upload vulnerability in fast-image-adder v1.1 Wordpress plugin

Fix: after 1.1
Fix from $2,300 2016-10-06
Mailcwp CRITICAL 9.8
CVE-2015-1000000

Remote file upload vulnerability in mailcwp v1.99 wordpress plugin

No fix yet
Fix from $2,300 2016-10-06
Readydesk CRITICAL 9.8
CVE-2016-5050

Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requ…

Mitigation only
Fix from $2,300 2016-08-26
Engineering Lifecycle Optimization Publishing MEDIUM 5.4
CVE-2016-2914

Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authe…

Patch available
Fix from $1,600 2016-08-08
Activemq CRITICAL 9.8
CVE-2016-3088 KEVEPSS 99%

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol…

Fix: 5.14.0+
Fix from $2,300 2016-06-01
Documentum Administrator MEDIUM 6.5
CVE-2015-4524

Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.…

Mitigation only
Fix from $1,600 2015-07-04
Unified Meetingplace HIGH 9.0
CVE-2015-0702

Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated…

Mitigation only
Fix from $1,950 2015-04-21
Ozzywork Galeri MEDIUM 6.4
CVE-2006-6994

Unrestricted file upload vulnerability in add.asp in OzzyWork Gallery, possibly 2.0 and earlier, allows remote attackers to upload and execute arbitr…

Fix: after 2.0
Fix from $1,600 2007-02-12
Speedywiki MEDIUM 6.5
CVE-2006-5845

Unrestricted file upload vulnerability in index.php in Speedywiki 2.0 allows remote authenticated users to upload and execute arbitrary PHP code by s…

Mitigation only
Fix from $1,600 2006-11-10
Deluxebb HIGH 7.5
CVE-2006-4558

DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uplo…

Fix: after 1.06
Fix from $1,950 2006-09-06