Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2015-6000EPSS 40% Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.p… Vtiger Crm after 6.3.0 Fix from $1,9502020-02-06 HIGH 8.8 CVE-2011-1597 OpenVAS Manager v2.0.3 allows plugin remote code execution. Openvas Manager No fix yet Fix from $1,9502020-02-06 CRITICAL 9.8 CVE-2020-6754EPSS 95% dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $… Dotcms 5.2.4+ Fix from $2,3002020-02-05 CRITICAL 9.8 CVE-2014-2025 Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x… Intrexx Mitigation only Fix from $2,3002020-01-31 CRITICAL 9.8 CVE-2020-8440 controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a r… Simplejobscript after 1.66 Fix from $2,3002020-01-31 CRITICAL 9.8 CVE-2013-2748EPSS 13% Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system. Wemo Switch Firmware No fix yet Fix from $2,3002020-01-28 HIGH 8.8 CVE-2020-7998 An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the develope… Super File Explorer Mitigation only Fix from $1,9502020-01-28 CRITICAL 9.8 CVE-2013-7390EPSS 75% Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attacke… Manageengine Desktop Central after 8.0.0 Fix from $2,3002020-01-27 CRITICAL 9.9 CVE-2020-6965 In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, … Apexpro Telemetry Server Firmware after 4.2 Fix from $2,3002020-01-24 CRITICAL 9.8 CVE-2012-6649EPSS 16% WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. Wp Gpx Maps Mitigation only Fix from $2,3002020-01-23 HIGH 7.2 CVE-2019-16514 An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administra… Control No fix yet Fix from $1,9502020-01-23 HIGH 8.8 CVE-2013-6358 PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ … Prestashop No fix yet Fix from $1,9502020-01-23 CRITICAL 9.8 CVE-2012-5190 Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability Prizm Content Connect No fix yet Fix from $2,3002020-01-21 HIGH 8.8 CVE-2020-7246EPSS 83% A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo fu… Qdpm after 9.1 Fix from $1,9502020-01-21 HIGH 8.8 CVE-2019-20385 The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content… Aware Callmanager No fix yet Fix from $1,9502020-01-21 MEDIUM 5.4 CVE-2020-2730 Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: File Uplo… Revenue Management And Billing Patch available Fix from $1,6002020-01-15 MEDIUM 5.3 CVE-2011-4907 Joomla! 1.5x through 1.5.12: Missing JEXEC Check Joomla\! after 1.5.12 Fix from $1,6002020-01-15 HIGH 7.2 CVE-2011-2933 An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files… Websitebaker after 2.8.1 Fix from $1,9502020-01-14 HIGH 7.2 CVE-2020-5509EPSS 6% PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image. Car Rental Portal No fix yet Fix from $1,9502020-01-14 HIGH 7.2 CVE-2019-20183EPSS 8% uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the cli… Employee Records System Mitigation only Fix from $1,9502020-01-09 HIGH 8.1 CVE-2012-2950 Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP c… Mapserver 3.0.6+ Fix from $1,9502020-01-09 CRITICAL 9.8 CVE-2012-2226EPSS 7% Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute… Invision Power Board 3.3.1+ Fix from $2,3002020-01-09 CRITICAL 9.8 CVE-2014-3448 BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload Bss Continuty Cms No fix yet Fix from $2,3002020-01-09 HIGH 8.8 CVE-2015-4553EPSS 57% A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell. Dedecms after 5.6 Fix from $1,9502020-01-06 CRITICAL 9.9 CVE-2015-5951 A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to… Fatca 5.2+ Fix from $2,3002020-01-06 HIGH 8.8 CVE-2020-5846 An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with t… Cloud Backup Suite No fix yet Fix from $1,9502020-01-06 CRITICAL 9.1 CVE-2020-5514EPSS 44% Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI. Gila Cms No fix yet Fix from $2,3002020-01-06 CRITICAL 9.8 CVE-2014-8516EPSS 82% Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with a… Netcharts Server No fix yet Fix from $2,3002020-01-03 CRITICAL 9.8 CVE-2014-8337 Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to ex… Helpdezk after 1.0.1 Fix from $2,3002020-01-03 HIGH 8.8 CVE-2019-16790 In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted. Tiny File Manager 2.3.9+ Fix from $1,9502019-12-30