Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-25537
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
Ucms
No fix yet
HIGH 8.8
CVE-2020-13671 KEV
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and …
Drupal
7.74 / 8.8.11+
HIGH 8.8
CVE-2020-7569
A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could ca…
Webreports
after 3.1
HIGH 7.3
CVE-2020-25406
app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files.
Lemocms
after 1.8.7
CRITICAL 9.8
CVE-2020-28130EPSS 7%
An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code …
Online Library Management System
No fix yet
CRITICAL 9.8
CVE-2020-26553
An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web …
Controller
No fix yet
HIGH 8.8
CVE-2020-28136
An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/cre…
Tourism Management System
No fix yet
CRITICAL 9.8
CVE-2020-28140
SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php.
Online Clothing Store
No fix yet
HIGH 8.8
CVE-2020-28687EPSS 12%
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Artworks Gallery In Php\, Css\, Javascript\, And Mysql
No fix yet
HIGH 8.8
CVE-2020-28688EPSS 12%
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Artworks Gallery In Php\, Css\, Javascript\, And Mysql
No fix yet
HIGH 8.8
CVE-2020-28693
An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploadin…
Horizontcms
No fix yet
HIGH 7.2
CVE-2020-28692
In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.
Gila Cms
No fix yet
CRITICAL 9.9
CVE-2020-13774
An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r…
Endpoint Manager
Mitigation only
HIGH 8.8
CVE-2020-27386EPSS 73%
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by usi…
Flexdotnetcms
1.5.9+
HIGH 8.8
CVE-2020-26803
In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload…
Sentrifugo
No fix yet
HIGH 8.8
CVE-2020-26804
In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with t…
Sentrifugo
No fix yet
HIGH 7.2
CVE-2020-26820
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator …
Netweaver Application Server Java
No fix yet
CRITICAL 9.8
CVE-2020-23138
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extensio…
Microweber
Mitigation only
CRITICAL 9.1
CVE-2020-24407EPSS 5%
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. T…
Magento
2.3.5+
HIGH 8.8
CVE-2020-28328EPSS 63%
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admi…
Suitecrm
7.11.17+
HIGH 8.8
CVE-2020-27387EPSS 18%
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to uploa…
Horizontcms
Patch available
HIGH 7.2
CVE-2020-15277
baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading …
Basercms
4.4.1+
HIGH 7.8
CVE-2020-4588
IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code …
I2 Ibase
after 8.9.13
CRITICAL 9.8
CVE-2020-11486
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows a…
Bmc Firmware
3.38.30+
HIGH 7.2
CVE-2020-8260 KEVEPSS 96%
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution …
Connect Secure
after 9.0
CRITICAL 9.8
CVE-2020-27956EPSS 5%
An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code exec…
Car Rental Management System
No fix yet
CRITICAL 9.8
CVE-2020-25483EPSS 9%
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the s…
Ucms
No fix yet
HIGH 8.6
CVE-2020-3436
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allo…
Adaptive Security Appliance
6.3.0.6 / 6.4.0.10+
MEDIUM 6.1
CVE-2020-26583
An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses c…
Sage Dpw
2020_06_002+
HIGH 8.8
CVE-2020-26048
The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and throu…
Cuppacms
2019-11-12+