Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2020-24986
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to mo…
Concrete Cms
after 8.5.2
HIGH 7.2
CVE-2020-14008EPSS 40%
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which l…
Manageengine Applications Manager
after 13.0
HIGH 7.2
CVE-2020-24948EPSS 13%
The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high pri…
Autoptimize
2.7.7+
HIGH 7.2
CVE-2020-25042EPSS 18%
An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session …
Maracms
No fix yet
HIGH 8.8
CVE-2020-14209EPSS 27%
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht a…
Dolibarr
11.0.5+
HIGH 8.8
CVE-2020-23829
interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers …
Librehealth Ehr
No fix yet
CRITICAL 9.8
CVE-2020-24202
File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote…
House Rental And Property Listing Project
No fix yet
CRITICAL 9.8
CVE-2020-24203
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1…
Travel Management System
No fix yet
HIGH 7.2
CVE-2020-24196
An Arbitrary File Upload in Vehicle Image Upload in Online Bike Rental v1.0 allows authenticated admin to conduct remote code execution.
Online Bike Rental
No fix yet
HIGH 7.5
CVE-2020-23972EPSS 31%
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can al…
Gmapfp
No fix yet
HIGH 8.8
CVE-2020-15645EPSS 11%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authent…
Qconvergeconsole
5.5.00.73+
CRITICAL 10.0
CVE-2020-24186EPSS 95%
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to u…
Wpdiscuz
after 7.0.4
HIGH 7.8
CVE-2020-22721
A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " E…
Pnotes.net
No fix yet
HIGH 7.8
CVE-2020-22722
Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker …
Rapid Scada
No fix yet
HIGH 7.8
CVE-2020-17462
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16…
Cms Made Simple
No fix yet
MEDIUM 6.4
CVE-2020-7302
Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to …
Data Loss Prevention
11.3.28 / 11.4.200+
MEDIUM 6.5
CVE-2020-6293
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to ac…
Netweaver Knowledge Management
Mitigation only
MEDIUM 5.5
CVE-2020-15649
Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actua…
Firefox Esr
68.11+
HIGH 7.2
CVE-2020-17452
flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
Flatcore
1.5.7+
HIGH 8.8
CVE-2020-14488
OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to upload and execute arbitrary file…
Openclinic Ga
Mitigation only
HIGH 7.2
CVE-2020-11476
Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
Concrete Cms
8.5.3+
HIGH 8.8
CVE-2020-9309
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML co…
Mimevalidator
2.0.0 / 4.6.0+
HIGH 8.8
CVE-2020-12854
A remote code execution vulnerability was identified in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can invoke code execution upon up…
Neprofile
No fix yet
MEDIUM 6.5
CVE-2020-14065
IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.
Mail Server
Mitigation only
HIGH 8.8
CVE-2020-14066
IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.
Mail Server
Mitigation only
HIGH 7.5
CVE-2020-1469
A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial of Service Vulnerability'.
Bond
Patch available
MEDIUM 6.5
CVE-2019-20897
The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a cr…
Jira
8.5.4 / 8.6.2+
HIGH 8.8
CVE-2020-13994EPSS 7%
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of i…
Mods For Hesk
after 2019.1.0
HIGH 8.8
CVE-2020-13443
ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Sav…
Expressionengine
5.3.2+
HIGH 8.8
CVE-2020-13887
documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to the documents folder.
Kordil Edms
2.2.60+