Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-8162
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows …
Rails
5.2.4.2 / 6.0.3.1+
HIGH 7.5
CVE-2020-12005
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:…
Factorytalk Linx
after 4.11.00
HIGH 8.0
CVE-2020-4470
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be…
Spectrum Protect Plus
after 10.1.5
CRITICAL 9.8
CVE-2020-14067
The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may con…
Navigatecms
Patch available
HIGH 7.2
CVE-2019-15123
The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a m…
Vera
Mitigation only
HIGH 7.2
CVE-2020-13852EPSS 28%
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.
Pandora Fms
No fix yet
HIGH 7.2
CVE-2020-13855EPSS 28%
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.
Pandora Fms
No fix yet
CRITICAL 9.8
CVE-2020-12800EPSS 79%
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution b…
Drag And Drop Multiple File Upload Contact Form 7
1.3.3.3+
MEDIUM 6.5
CVE-2018-21243
An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used.
Phantompdf
8.3.6+
CRITICAL 9.8
CVE-2018-21244
An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded executable file in a PDF portfoli…
Phantompdf
8.3.6+
HIGH 8.0
CVE-2020-12846
Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is potential abuse of /service/uplo…
Zimbra Collaboration Suite
8.8.15+
HIGH 8.8
CVE-2020-12675
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related t…
Mappress
2.54.6+
CRITICAL 9.8
CVE-2020-13442
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp hand…
Dext5
after 2.7.1402870
HIGH 8.8
CVE-2020-13384
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example…
Monstra
No fix yet
HIGH 8.5
CVE-2020-1112
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded…
Windows 10
Patch available
HIGH 8.8
CVE-2020-1102EPSS 5%
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An…
Sharepoint Enterprise Server
Patch available
HIGH 8.8
CVE-2020-1023
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An…
Sharepoint Enterprise Server
Patch available
HIGH 8.8
CVE-2020-1024
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An…
Sharepoint Enterprise Server
Patch available
CRITICAL 9.8
CVE-2020-12828
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localho…
Virtual Private Network Software Development Kit
1.3.3.218+
HIGH 7.8
CVE-2020-13241
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (u…
Microweber
No fix yet
HIGH 7.8
CVE-2020-11807
Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP cod…
Newscoop
Patch available
HIGH 8.8
CVE-2020-12255EPSS 53%
rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file uplo…
Rconfig
Mitigation only
HIGH 7.5
CVE-2020-13128
An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that ca…
Gwtupload
No fix yet
CRITICAL 9.9
CVE-2020-13126EPSS 9%
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-131…
Elementor Page Builder
2.9.4+
HIGH 8.8
CVE-2020-5577
Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Adv…
Movable Type
after 7.2.1
HIGH 8.8
CVE-2020-11108EPSS 78%
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution …
Pi Hole
after 4.4
HIGH 7.1
CVE-2020-5880
Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, b…
Big Ip Access Policy Manager
after 15.0.1.3
HIGH 8.8
CVE-2020-11943EPSS 24%
An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.
Open Audit
No fix yet
MEDIUM 6.2
CVE-2020-12252
An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an execu…
Gigavue
5.4.04 / 5.5.02+
CRITICAL 9.8
CVE-2020-11817
In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacke…
Rukovoditel
No fix yet