Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.5 CVE-2020-8162 A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows … Rails 5.2.4.2 / 6.0.3.1+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2020-12005 FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:… Factorytalk Linx after 4.11.00 Fix from $1,9502020-06-15 HIGH 8.0 CVE-2020-4470 IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be… Spectrum Protect Plus after 10.1.5 Fix from $1,9502020-06-15 CRITICAL 9.8 CVE-2020-14067 The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may con… Navigatecms Patch available Fix from $2,3002020-06-15 HIGH 7.2 CVE-2019-15123 The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a m… Vera Mitigation only Fix from $1,9502020-06-12 HIGH 7.2 CVE-2020-13852EPSS 28% Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature. Pandora Fms No fix yet Fix from $1,9502020-06-11 HIGH 7.2 CVE-2020-13855EPSS 28% Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature. Pandora Fms No fix yet Fix from $1,9502020-06-11 CRITICAL 9.8 CVE-2020-12800EPSS 79% The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution b… Drag And Drop Multiple File Upload Contact Form 7 1.3.3.3+ Fix from $2,3002020-06-08 MEDIUM 6.5 CVE-2018-21243 An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used. Phantompdf 8.3.6+ Fix from $1,6002020-06-04 CRITICAL 9.8 CVE-2018-21244 An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded executable file in a PDF portfoli… Phantompdf 8.3.6+ Fix from $2,3002020-06-04 HIGH 8.0 CVE-2020-12846 Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is potential abuse of /service/uplo… Zimbra Collaboration Suite 8.8.15+ Fix from $1,9502020-06-03 HIGH 8.8 CVE-2020-12675 The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related t… Mappress 2.54.6+ Fix from $1,9502020-05-29 CRITICAL 9.8 CVE-2020-13442 A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp hand… Dext5 after 2.7.1402870 Fix from $2,3002020-05-25 HIGH 8.8 CVE-2020-13384 Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example… Monstra No fix yet Fix from $1,9502020-05-22 HIGH 8.5 CVE-2020-1112 An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded… Windows 10 Patch available Fix from $1,9502020-05-21 HIGH 8.8 CVE-2020-1102EPSS 5% A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An… Sharepoint Enterprise Server Patch available Fix from $1,9502020-05-21 HIGH 8.8 CVE-2020-1023 A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An… Sharepoint Enterprise Server Patch available Fix from $1,9502020-05-21 HIGH 8.8 CVE-2020-1024 A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An… Sharepoint Enterprise Server Patch available Fix from $1,9502020-05-21 CRITICAL 9.8 CVE-2020-12828 An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localho… Virtual Private Network Software Development Kit 1.3.3.218+ Fix from $2,3002020-05-21 HIGH 7.8 CVE-2020-13241 Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (u… Microweber No fix yet Fix from $1,9502020-05-20 HIGH 7.8 CVE-2020-11807 Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP cod… Newscoop Patch available Fix from $1,9502020-05-19 HIGH 8.8 CVE-2020-12255EPSS 53% rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file uplo… Rconfig Mitigation only Fix from $1,9502020-05-18 HIGH 7.5 CVE-2020-13128 An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that ca… Gwtupload No fix yet Fix from $1,9502020-05-18 CRITICAL 9.9 CVE-2020-13126EPSS 9% An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-131… Elementor Page Builder 2.9.4+ Fix from $2,3002020-05-17 HIGH 8.8 CVE-2020-5577 Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Adv… Movable Type after 7.2.1 Fix from $1,9502020-05-14 HIGH 8.8 CVE-2020-11108EPSS 78% The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution … Pi Hole after 4.4 Fix from $1,9502020-05-11 HIGH 7.1 CVE-2020-5880 Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, b… Big Ip Access Policy Manager after 15.0.1.3 Fix from $1,9502020-04-30 HIGH 8.8 CVE-2020-11943EPSS 24% An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload. Open Audit No fix yet Fix from $1,9502020-04-29 MEDIUM 6.2 CVE-2020-12252 An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an execu… Gigavue 5.4.04 / 5.5.02+ Fix from $1,6002020-04-29 CRITICAL 9.8 CVE-2020-11817 In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacke… Rukovoditel No fix yet Fix from $2,3002020-04-27