Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2020-24986 Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to mo… Concrete Cms after 8.5.2 Fix from $1,9502020-09-04 HIGH 7.2 CVE-2020-14008EPSS 40% Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which l… Manageengine Applications Manager after 13.0 Fix from $1,9502020-09-04 HIGH 7.2 CVE-2020-24948EPSS 13% The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high pri… Autoptimize 2.7.7+ Fix from $1,9502020-09-03 HIGH 7.2 CVE-2020-25042EPSS 18% An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session … Maracms No fix yet Fix from $1,9502020-09-03 HIGH 8.8 CVE-2020-14209EPSS 27% Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht a… Dolibarr 11.0.5+ Fix from $1,9502020-09-02 HIGH 8.8 CVE-2020-23829 interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers … Librehealth Ehr No fix yet Fix from $1,9502020-09-01 CRITICAL 9.8 CVE-2020-24202 File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote… House Rental And Property Listing Project No fix yet Fix from $2,3002020-08-27 CRITICAL 9.8 CVE-2020-24203 Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1… Travel Management System No fix yet Fix from $2,3002020-08-27 HIGH 7.2 CVE-2020-24196 An Arbitrary File Upload in Vehicle Image Upload in Online Bike Rental v1.0 allows authenticated admin to conduct remote code execution. Online Bike Rental No fix yet Fix from $1,9502020-08-27 HIGH 7.5 CVE-2020-23972EPSS 31% In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can al… Gmapfp No fix yet Fix from $1,9502020-08-27 HIGH 8.8 CVE-2020-15645EPSS 11% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authent… Qconvergeconsole 5.5.00.73+ Fix from $1,9502020-08-25 CRITICAL 10.0 CVE-2020-24186EPSS 95% A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to u… Wpdiscuz after 7.0.4 Fix from $2,3002020-08-24 HIGH 7.8 CVE-2020-22721 A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " E… Pnotes.net No fix yet Fix from $1,9502020-08-14 HIGH 7.8 CVE-2020-22722 Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker … Rapid Scada No fix yet Fix from $1,9502020-08-14 HIGH 7.8 CVE-2020-17462 CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16… Cms Made Simple No fix yet Fix from $1,9502020-08-14 MEDIUM 6.4 CVE-2020-7302 Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to … Data Loss Prevention 11.3.28 / 11.4.200+ Fix from $1,6002020-08-13 MEDIUM 6.5 CVE-2020-6293 SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to ac… Netweaver Knowledge Management Mitigation only Fix from $1,6002020-08-12 MEDIUM 5.5 CVE-2020-15649 Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actua… Firefox Esr 68.11+ Fix from $1,6002020-08-10 HIGH 7.2 CVE-2020-17452 flatCore before 1.5.7 allows upload and execution of a .php file by an admin. Flatcore 1.5.7+ Fix from $1,9502020-08-09 HIGH 8.8 CVE-2020-14488 OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to upload and execute arbitrary file… Openclinic Ga Mitigation only Fix from $1,9502020-07-29 HIGH 7.2 CVE-2020-11476 Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file. Concrete Cms 8.5.3+ Fix from $1,9502020-07-28 HIGH 8.8 CVE-2020-9309 Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML co… Mimevalidator 2.0.0 / 4.6.0+ Fix from $1,9502020-07-15 HIGH 8.8 CVE-2020-12854 A remote code execution vulnerability was identified in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can invoke code execution upon up… Neprofile No fix yet Fix from $1,9502020-07-15 MEDIUM 6.5 CVE-2020-14065 IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space. Mail Server Mitigation only Fix from $1,6002020-07-15 HIGH 8.8 CVE-2020-14066 IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access. Mail Server Mitigation only Fix from $1,9502020-07-15 HIGH 7.5 CVE-2020-1469 A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial of Service Vulnerability'. Bond Patch available Fix from $1,9502020-07-14 MEDIUM 6.5 CVE-2019-20897 The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a cr… Jira 8.5.4 / 8.6.2+ Fix from $1,6002020-07-13 HIGH 8.8 CVE-2020-13994EPSS 7% An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of i… Mods For Hesk after 2019.1.0 Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-13443 ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Sav… Expressionengine 5.3.2+ Fix from $1,9502020-06-24 HIGH 8.8 CVE-2020-13887 documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to the documents folder. Kordil Edms 2.2.60+ Fix from $1,9502020-06-22