Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2019-20048EPSS 6%
An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web …
Omnivista 8770
4.1.12+
HIGH 8.8
CVE-2013-4796
ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
Reviewboard
Mitigation only
HIGH 7.5
CVE-2019-19925EPSS 7%
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
SQLite
1.0.1.1+
CRITICAL 9.8
CVE-2019-8293
Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.
Upload Image With Ajax
Patch available
CRITICAL 9.8
CVE-2019-19634
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .ph…
K2
1.0.3 / 2.0.4+
HIGH 8.8
CVE-2019-19745
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute th…
Contao
after 4.8.5
CRITICAL 9.8
CVE-2019-18313
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could …
Sppa T3000 Ms3000 Migration Server
Mitigation only
HIGH 7.5
CVE-2019-18320
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…
Sppa T3000 Application Server
Mitigation only
HIGH 8.8
CVE-2019-18288
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with valid authentication at…
Sppa T3000 Application Server
No fix yet
CRITICAL 9.8
CVE-2019-15936
Intesync Solismed 3.3sp allows Insecure File Upload.
Solismed
No fix yet
HIGH 8.8
CVE-2019-4612
IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malici…
Planning Analytics
Mitigation only
HIGH 8.8
CVE-2019-19684
nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/Facebook…
Nopcommerce
No fix yet
HIGH 8.8
CVE-2012-1592EPSS 29%
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit…
Struts
Mitigation only
CRITICAL 9.8
CVE-2019-19594
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute…
Prestashop
No fix yet
CRITICAL 9.8
CVE-2019-19595
reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers…
Prestashop
No fix yet
MEDIUM 6.5
CVE-2019-11216
BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attack…
Remedy Smart Reporting
after 19.02.01
CRITICAL 9.8
CVE-2019-19576EPSS 26%
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar…
K2
1.0.3 / 2.0.4+
HIGH 8.8
CVE-2019-4130
IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary cod…
Cloud Pak System
Patch available
HIGH 7.2
CVE-2019-19020
An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted backup file that enab…
Webtitan
5.18+
MEDIUM 5.4
CVE-2019-19493
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
Xperience
12.0.50+
HIGH 7.8
CVE-2019-19468
Free Photo Viewer 1.3 allows remote attackers to execute arbitrary code via a crafted BMP and/or TIFF file that triggers a malformed SEH, as demonstr…
Free Photo Viewer
No fix yet
HIGH 8.8
CVE-2019-17403
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
Impact
18a+
HIGH 8.0
CVE-2013-6234EPSS 7%
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by…
Spagobi
4.1+
CRITICAL 9.8
CVE-2019-12409EPSS 22%
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh…
Solr
No fix yet
CRITICAL 9.8
CVE-2019-12271
Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded file…
Centraleyezer
No fix yet
HIGH 7.8
CVE-2019-14467
The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover p…
Social Photo Gallery
No fix yet
CRITICAL 9.1
CVE-2019-17058
Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a whitelist can be bypassed by a…
Tipping Software
Mitigation only
CRITICAL 9.8
CVE-2019-18952EPSS 45%
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execu…
Xfilesharing
after 2.5.1
HIGH 7.8
CVE-2010-4661
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
Debian Linux
1.0.3+
HIGH 8.8
CVE-2014-1214
views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute ar…
Smart Flash Header
after 3.0.2