Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2020-12077EPSS 6%
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability chec…
Mappress
2.53.9+
CRITICAL 9.9
CVE-2020-7055
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to exe…
Elementor Page Builder
after 2.7.4
HIGH 8.8
CVE-2020-11011
In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arbitrary code. This is patched …
Phproject
1.7.8+
CRITICAL 9.8
CVE-2020-10569
SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticate…
On Premise
No fix yet
CRITICAL 9.8
CVE-2020-11811
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type va…
Qdpm
No fix yet
CRITICAL 9.8
CVE-2020-11815
In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can…
Rukovoditel
No fix yet
HIGH 7.5
CVE-2020-9280
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder inste…
Silverstripe
after 4.5.0
HIGH 8.8
CVE-2020-0971EPSS 13%
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…
Sharepoint Enterprise Server
Patch available
HIGH 8.8
CVE-2020-0974EPSS 11%
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…
Sharepoint Enterprise Server
Patch available
HIGH 8.8
CVE-2020-0929EPSS 11%
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…
Sharepoint Enterprise Server
Patch available
HIGH 8.8
CVE-2020-0931EPSS 11%
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…
Business Productivity Servers
Patch available
HIGH 8.8
CVE-2020-0932EPSS 31%
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…
Sharepoint Enterprise Server
Patch available
HIGH 8.8
CVE-2020-0920EPSS 10%
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…
Sharepoint Enterprise Server
Patch available
CRITICAL 9.8
CVE-2020-10507
The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Unrestricted file upload (RCE) , that woul…
The School Manage System
Mitigation only
CRITICAL 9.8
CVE-2020-11722
Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .…
Dungeon Crawl Stone Soup
0.25+
CRITICAL 9.8
CVE-2020-10621
Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).
Webaccess\/nms
3.0.2+
CRITICAL 9.8
CVE-2020-11598
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and exe…
Cipace
9.1+
HIGH 7.2
CVE-2020-11544
An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account bec…
Official Car Rental System
No fix yet
HIGH 8.8
CVE-2020-8639EPSS 16%
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a f…
Testlink
Patch available
HIGH 7.2
CVE-2020-11451
The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files with arbit…
Microstrategy Web
after 10.4
CRITICAL 9.8
CVE-2020-6008
LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution
Lifterlms
3.37.15+
HIGH 7.2
CVE-2020-10963EPSS 15%
FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/f…
Laravel Administrator
after 5.0.12
CRITICAL 9.8
CVE-2020-10964
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This…
Serendipity
2.3.4+
HIGH 7.2
CVE-2020-10934
Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.
Acymailing
6.9.2+
MEDIUM 6.5
CVE-2020-8866EPSS 10%
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authenticat…
Debian Linux
2.0.20+
HIGH 7.2
CVE-2020-7935
Artica Pandora FMS through 7.42 is vulnerable to remote PHP code execution because of an Unrestricted Upload Of A File With A Dangerous Type issue in…
Pandora Fms
after 7.42
HIGH 7.2
CVE-2020-8511
In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a differen…
Pandora Fms
after 7.42
CRITICAL 9.8
CVE-2020-10806
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 20…
Ez Publish Kernel
5.4.14.1 / 6.13.6.2+
HIGH 7.8
CVE-2020-10682
The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinter…
Cms Made Simple
No fix yet
HIGH 8.8
CVE-2019-16066
An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attac…
Enigma Network Management Solution
after 65.0.0