Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2019-20048EPSS 6% An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web … Omnivista 8770 4.1.12+ Fix from $1,9502019-12-27 HIGH 8.8 CVE-2013-4796 ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request Reviewboard Mitigation only Fix from $1,9502019-12-27 HIGH 7.5 CVE-2019-19925EPSS 7% zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive. SQLite 1.0.1.1+ Fix from $1,9502019-12-24 CRITICAL 9.8 CVE-2019-8293 Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution. Upload Image With Ajax Patch available Fix from $2,3002019-12-23 CRITICAL 9.8 CVE-2019-19634 class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .ph… K2 1.0.3 / 2.0.4+ Fix from $2,3002019-12-17 HIGH 8.8 CVE-2019-19745 Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute th… Contao after 4.8.5 Fix from $1,9502019-12-17 CRITICAL 9.8 CVE-2019-18313 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could … Sppa T3000 Ms3000 Migration Server Mitigation only Fix from $2,3002019-12-12 HIGH 7.5 CVE-2019-18320 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A… Sppa T3000 Application Server Mitigation only Fix from $1,9502019-12-12 HIGH 8.8 CVE-2019-18288 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with valid authentication at… Sppa T3000 Application Server No fix yet Fix from $1,9502019-12-12 CRITICAL 9.8 CVE-2019-15936 Intesync Solismed 3.3sp allows Insecure File Upload. Solismed No fix yet Fix from $2,3002019-12-12 HIGH 8.8 CVE-2019-4612 IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malici… Planning Analytics Mitigation only Fix from $1,9502019-12-09 HIGH 8.8 CVE-2019-19684 nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/Facebook… Nopcommerce No fix yet Fix from $1,9502019-12-09 HIGH 8.8 CVE-2012-1592EPSS 29% A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit… Struts Mitigation only Fix from $1,9502019-12-05 CRITICAL 9.8 CVE-2019-19594 reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute… Prestashop No fix yet Fix from $2,3002019-12-05 CRITICAL 9.8 CVE-2019-19595 reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers… Prestashop No fix yet Fix from $2,3002019-12-05 MEDIUM 6.5 CVE-2019-11216 BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attack… Remedy Smart Reporting after 19.02.01 Fix from $1,6002019-12-04 CRITICAL 9.8 CVE-2019-19576EPSS 26% class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar… K2 1.0.3 / 2.0.4+ Fix from $2,3002019-12-04 HIGH 8.8 CVE-2019-4130 IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary cod… Cloud Pak System Patch available Fix from $1,9502019-12-03 HIGH 7.2 CVE-2019-19020 An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted backup file that enab… Webtitan 5.18+ Fix from $1,9502019-12-02 MEDIUM 5.4 CVE-2019-19493 Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS. Xperience 12.0.50+ Fix from $1,6002019-12-02 HIGH 7.8 CVE-2019-19468 Free Photo Viewer 1.3 allows remote attackers to execute arbitrary code via a crafted BMP and/or TIFF file that triggers a malformed SEH, as demonstr… Free Photo Viewer No fix yet Fix from $1,9502019-11-30 HIGH 8.8 CVE-2019-17403 Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution. Impact 18a+ Fix from $1,9502019-11-25 HIGH 8.0 CVE-2013-6234EPSS 7% Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by… Spagobi 4.1+ Fix from $1,9502019-11-22 CRITICAL 9.8 CVE-2019-12409EPSS 22% The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh… Solr No fix yet Fix from $2,3002019-11-18 CRITICAL 9.8 CVE-2019-12271 Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded file… Centraleyezer No fix yet Fix from $2,3002019-11-18 HIGH 7.8 CVE-2019-14467 The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover p… Social Photo Gallery No fix yet Fix from $1,9502019-11-18 CRITICAL 9.1 CVE-2019-17058 Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a whitelist can be bypassed by a… Tipping Software Mitigation only Fix from $2,3002019-11-18 CRITICAL 9.8 CVE-2019-18952EPSS 45% SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execu… Xfilesharing after 2.5.1 Fix from $2,3002019-11-13 HIGH 7.8 CVE-2010-4661 udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. Debian Linux 1.0.3+ Fix from $1,9502019-11-13 HIGH 8.8 CVE-2014-1214 views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute ar… Smart Flash Header after 3.0.2 Fix from $1,9502019-11-13