Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2020-12715 RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control. Pacsone Server No fix yet Fix from $1,9502020-09-30 HIGH 7.5 CVE-2020-15488 Re:Desk 2.3 allows insecure file upload. Re\ No fix yet Fix from $1,9502020-09-30 CRITICAL 9.8 CVE-2020-25763 Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution… Seat Reservation System No fix yet Fix from $2,3002020-09-30 HIGH 8.8 CVE-2020-21564 An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin… Pluck No fix yet Fix from $1,9502020-09-30 CRITICAL 9.8 CVE-2020-19672 Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface, through parameter upload, b… Niushop No fix yet Fix from $2,3002020-09-30 HIGH 8.8 CVE-2020-25144 An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio… Observium Mitigation only Fix from $1,9502020-09-25 HIGH 8.8 CVE-2020-25145 An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio… Observium Mitigation only Fix from $1,9502020-09-25 HIGH 8.8 CVE-2020-25149 An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio… Observium Mitigation only Fix from $1,9502020-09-25 HIGH 8.8 CVE-2020-25136 An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio… Observium No fix yet Fix from $1,9502020-09-25 HIGH 8.8 CVE-2020-25134 An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio… Observium Mitigation only Fix from $1,9502020-09-25 HIGH 8.8 CVE-2020-25133 An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio… Observium Mitigation only Fix from $1,9502020-09-25 CRITICAL 9.8 CVE-2020-12843 ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV must be used. Ismartgate Pro Firmware No fix yet Fix from $2,3002020-09-24 HIGH 7.5 CVE-2020-12837 ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG must be used. Ismartgate Pro Firmware No fix yet Fix from $1,9502020-09-24 HIGH 7.2 CVE-2019-1888 A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attack… Unified Contact Center Express Mitigation only Fix from $1,9502020-09-23 HIGH 7.8 CVE-2020-25515 Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<site>/lms/index.php?page=books. Simple Library Management System No fix yet Fix from $1,9502020-09-22 HIGH 8.8 CVE-2020-14022 Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a fil… Ozeki Ng Sms Gateway after 4.17.6 Fix from $1,9502020-09-22 MEDIUM 6.5 CVE-2020-15839 Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data PO… Digital Experience Platform 7.3.3+ Fix from $1,6002020-09-22 HIGH 8.8 CVE-2020-4620EPSS 5% IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file e… Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 HIGH 7.2 CVE-2020-25790EPSS 16% Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes… Typesetter after 5.1 Fix from $1,9502020-09-19 HIGH 7.2 CVE-2020-15189 SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was… Soy Cms 3.0.2.328+ Fix from $1,9502020-09-18 HIGH 7.5 CVE-2020-25733 webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types. Webtareas after 2.1 Fix from $1,9502020-09-18 MEDIUM 6.1 CVE-2020-13260 A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScri… Secflow 1v Firmware No fix yet Fix from $1,6002020-09-17 CRITICAL 9.8 CVE-2020-23828 A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the h… Online Course Registration No fix yet Fix from $2,3002020-09-15 HIGH 8.0 CVE-2020-4703 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be… Spectrum Protect Plus after 10.1.6 Fix from $1,9502020-09-15 HIGH 8.8 CVE-2020-10228 A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execut… Vtenext No fix yet Fix from $1,9502020-09-14 HIGH 7.2 CVE-2020-25287 Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admi… Pligg No fix yet Fix from $1,9502020-09-13 CRITICAL 9.8 CVE-2020-25213 KEVEPSS 97% The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it rename… File Manager 6.9+ Fix from $2,3002020-09-09 CRITICAL 9.1 CVE-2020-24195 An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote… Online Bike Rental No fix yet Fix from $2,3002020-09-09 CRITICAL 9.8 CVE-2020-24199 Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote co… Car Rental Project No fix yet Fix from $2,3002020-09-09 MEDIUM 5.3 CVE-2020-6288 SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-09-09