Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2020-25537 File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission. Ucms No fix yet Fix from $2,3002020-11-30 HIGH 8.8 CVE-2020-13671 KEV Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and … Drupal 7.74 / 8.8.11+ Fix from $1,9502020-11-20 HIGH 8.8 CVE-2020-7569 A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could ca… Webreports after 3.1 Fix from $1,9502020-11-19 HIGH 7.3 CVE-2020-25406 app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files. Lemocms after 1.8.7 Fix from $1,9502020-11-18 CRITICAL 9.8 CVE-2020-28130EPSS 7% An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code … Online Library Management System No fix yet Fix from $2,3002020-11-17 CRITICAL 9.8 CVE-2020-26553 An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web … Controller No fix yet Fix from $2,3002020-11-17 HIGH 8.8 CVE-2020-28136 An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/cre… Tourism Management System No fix yet Fix from $1,9502020-11-17 CRITICAL 9.8 CVE-2020-28140 SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php. Online Clothing Store No fix yet Fix from $2,3002020-11-17 HIGH 8.8 CVE-2020-28687EPSS 12% The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files. Artworks Gallery In Php\, Css\, Javascript\, And Mysql No fix yet Fix from $1,9502020-11-17 HIGH 8.8 CVE-2020-28688EPSS 12% The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files. Artworks Gallery In Php\, Css\, Javascript\, And Mysql No fix yet Fix from $1,9502020-11-17 HIGH 8.8 CVE-2020-28693 An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploadin… Horizontcms No fix yet Fix from $1,9502020-11-16 HIGH 7.2 CVE-2020-28692 In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files. Gila Cms No fix yet Fix from $1,9502020-11-16 CRITICAL 9.9 CVE-2020-13774 An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r… Endpoint Manager Mitigation only Fix from $2,3002020-11-12 HIGH 8.8 CVE-2020-27386EPSS 73% An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by usi… Flexdotnetcms 1.5.9+ Fix from $1,9502020-11-12 HIGH 8.8 CVE-2020-26803 In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload… Sentrifugo No fix yet Fix from $1,9502020-11-12 HIGH 8.8 CVE-2020-26804 In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with t… Sentrifugo No fix yet Fix from $1,9502020-11-12 HIGH 7.2 CVE-2020-26820 SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator … Netweaver Application Server Java No fix yet Fix from $1,9502020-11-10 CRITICAL 9.8 CVE-2020-23138 An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extensio… Microweber Mitigation only Fix from $2,3002020-11-09 CRITICAL 9.1 CVE-2020-24407EPSS 5% Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. T… Magento 2.3.5+ Fix from $2,3002020-11-09 HIGH 8.8 CVE-2020-28328EPSS 63% SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admi… Suitecrm 7.11.17+ Fix from $1,9502020-11-06 HIGH 8.8 CVE-2020-27387EPSS 18% An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to uploa… Horizontcms Patch available Fix from $1,9502020-11-05 HIGH 7.2 CVE-2020-15277 baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading … Basercms 4.4.1+ Fix from $1,9502020-10-30 HIGH 7.8 CVE-2020-4588 IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code … I2 Ibase after 8.9.13 Fix from $1,9502020-10-30 CRITICAL 9.8 CVE-2020-11486 NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows a… Bmc Firmware 3.38.30+ Fix from $2,3002020-10-29 HIGH 7.2 CVE-2020-8260 KEVEPSS 96% A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution … Connect Secure after 9.0 Fix from $1,9502020-10-28 CRITICAL 9.8 CVE-2020-27956EPSS 5% An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code exec… Car Rental Management System No fix yet Fix from $2,3002020-10-28 CRITICAL 9.8 CVE-2020-25483EPSS 9% An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the s… Ucms No fix yet Fix from $2,3002020-10-23 HIGH 8.6 CVE-2020-3436 A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allo… Adaptive Security Appliance 6.3.0.6 / 6.4.0.10+ Fix from $1,9502020-10-21 MEDIUM 6.1 CVE-2020-26583 An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses c… Sage Dpw 2020_06_002+ Fix from $1,6002020-10-16 HIGH 8.8 CVE-2020-26048 The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and throu… Cuppacms 2019-11-12+ Fix from $1,9502020-10-05