Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2020-12077EPSS 6% The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability chec… Mappress 2.53.9+ Fix from $1,9502020-04-23 CRITICAL 9.9 CVE-2020-7055 An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to exe… Elementor Page Builder after 2.7.4 Fix from $2,3002020-04-22 HIGH 8.8 CVE-2020-11011 In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arbitrary code. This is patched … Phproject 1.7.8+ Fix from $1,9502020-04-22 CRITICAL 9.8 CVE-2020-10569 SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticate… On Premise No fix yet Fix from $2,3002020-04-21 CRITICAL 9.8 CVE-2020-11811 In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type va… Qdpm No fix yet Fix from $2,3002020-04-16 CRITICAL 9.8 CVE-2020-11815 In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can… Rukovoditel No fix yet Fix from $2,3002020-04-16 HIGH 7.5 CVE-2020-9280 In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder inste… Silverstripe after 4.5.0 Fix from $1,9502020-04-15 HIGH 8.8 CVE-2020-0971EPSS 13% A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak… Sharepoint Enterprise Server Patch available Fix from $1,9502020-04-15 HIGH 8.8 CVE-2020-0974EPSS 11% A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak… Sharepoint Enterprise Server Patch available Fix from $1,9502020-04-15 HIGH 8.8 CVE-2020-0929EPSS 11% A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak… Sharepoint Enterprise Server Patch available Fix from $1,9502020-04-15 HIGH 8.8 CVE-2020-0931EPSS 11% A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak… Business Productivity Servers Patch available Fix from $1,9502020-04-15 HIGH 8.8 CVE-2020-0932EPSS 31% A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak… Sharepoint Enterprise Server Patch available Fix from $1,9502020-04-15 HIGH 8.8 CVE-2020-0920EPSS 10% A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak… Sharepoint Enterprise Server Patch available Fix from $1,9502020-04-15 CRITICAL 9.8 CVE-2020-10507 The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Unrestricted file upload (RCE) , that woul… The School Manage System Mitigation only Fix from $2,3002020-04-15 CRITICAL 9.8 CVE-2020-11722 Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .… Dungeon Crawl Stone Soup 0.25+ Fix from $2,3002020-04-12 CRITICAL 9.8 CVE-2020-10621 Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2). Webaccess\/nms 3.0.2+ Fix from $2,3002020-04-09 CRITICAL 9.8 CVE-2020-11598 An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and exe… Cipace 9.1+ Fix from $2,3002020-04-06 HIGH 7.2 CVE-2020-11544 An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account bec… Official Car Rental System No fix yet Fix from $1,9502020-04-06 HIGH 8.8 CVE-2020-8639EPSS 16% An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a f… Testlink Patch available Fix from $1,9502020-04-03 HIGH 7.2 CVE-2020-11451 The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files with arbit… Microstrategy Web after 10.4 Fix from $1,9502020-04-02 CRITICAL 9.8 CVE-2020-6008 LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution Lifterlms 3.37.15+ Fix from $2,3002020-03-31 HIGH 7.2 CVE-2020-10963EPSS 15% FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/f… Laravel Administrator after 5.0.12 Fix from $1,9502020-03-25 CRITICAL 9.8 CVE-2020-10964 Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This… Serendipity 2.3.4+ Fix from $2,3002020-03-25 HIGH 7.2 CVE-2020-10934 Acyba AcyMailing before 6.9.2 mishandles file uploads by admins. Acymailing 6.9.2+ Fix from $1,9502020-03-24 MEDIUM 6.5 CVE-2020-8866EPSS 10% This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authenticat… Debian Linux 2.0.20+ Fix from $1,6002020-03-23 HIGH 7.2 CVE-2020-7935 Artica Pandora FMS through 7.42 is vulnerable to remote PHP code execution because of an Unrestricted Upload Of A File With A Dangerous Type issue in… Pandora Fms after 7.42 Fix from $1,9502020-03-23 HIGH 7.2 CVE-2020-8511 In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a differen… Pandora Fms after 7.42 Fix from $1,9502020-03-23 CRITICAL 9.8 CVE-2020-10806 eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 20… Ez Publish Kernel 5.4.14.1 / 6.13.6.2+ Fix from $2,3002020-03-22 HIGH 7.8 CVE-2020-10682 The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinter… Cms Made Simple No fix yet Fix from $1,9502020-03-20 HIGH 8.8 CVE-2019-16066 An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attac… Enigma Network Management Solution after 65.0.0 Fix from $1,9502020-03-19