Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2019-1443EPSS 5%
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An …
Sharepoint Enterprise Server
Patch available
CRITICAL 9.8
CVE-2019-12719
An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnera…
Sunveillance Monitoring System \& Data Recorder
1.1.9e+
HIGH 7.2
CVE-2019-8114
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2…
Magento
1.9.4.3 / 1.14.4.3+
HIGH 8.8
CVE-2019-8093
An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can lever…
Magento
2.2.10 / 2.3.2+
CRITICAL 9.8
CVE-2011-1134
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the im…
Serendipity
1.5.5+
HIGH 8.8
CVE-2010-3663
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPatter…
TYPO3
4.1.14 / 4.2.13+
MEDIUM 6.5
CVE-2019-17325
ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. T…
Rexpert
after 1.0.0.527
HIGH 8.8
CVE-2019-18204
Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.
Infobusiness
after 4.4.1
HIGH 8.8
CVE-2018-18930
The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature…
Carousel Digital Signage
after 7.0.4.104
CRITICAL 9.8
CVE-2019-14451
RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when uploading a new printer config…
Repetier Server
after 0.91
HIGH 8.8
CVE-2019-18417
Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The iss…
Restaurant Management System
No fix yet
HIGH 7.2
CVE-2019-11021
admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE: "While inadverten…
Cms
Mitigation only
CRITICAL 9.8
CVE-2015-9499EPSS 16%
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
Showbiz Pro
after 1.7.1
HIGH 7.2
CVE-2019-16530
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Nexus Iq Server
after 72
CRITICAL 9.8
CVE-2019-16700
The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1…
Slub Events
after 3.0.2
HIGH 8.8
CVE-2019-17490
app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by PHP code…
Jiangnan Online Judge
No fix yet
CRITICAL 9.8
CVE-2015-9479
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upl…
Acf Fronted Display
after 2015-07-03
CRITICAL 9.8
CVE-2015-9471
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
Zoomsounds
after 2.0
CRITICAL 9.8
CVE-2018-21024
licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
Centreon
2.8.27+
HIGH 8.8
CVE-2019-14656
Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user)…
Vp59 Firmware
after 2019-08-04
HIGH 8.8
CVE-2019-14657
Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extracti…
Vp59 Firmware
after 2019-08-04
HIGH 7.5
CVE-2019-17352
In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type o…
Jfinal
4.4+
CRITICAL 9.8
CVE-2019-15748
SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticate…
Sitos Six
Mitigation only
CRITICAL 9.8
CVE-2019-15751
An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with …
Sitos Six
Mitigation only
HIGH 7.2
CVE-2019-17188
An unrestricted file upload vulnerability was discovered in catalog/productinfo/imageupload in Fecshop FecMall 2.3.4. An attacker can bypass a front-…
Fecmall
No fix yet
HIGH 8.8
CVE-2019-11655
Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of…
Arcsight Logger
Mitigation only
HIGH 8.8
CVE-2019-15766
The KSLABS KSWEB (aka ru.kslabs.ksweb) application 3.93 for Android allows authenticated remote code execution via a POST request to the AJAX handler…
Ksweb
No fix yet
HIGH 7.2
CVE-2019-17046
Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page.
Ilch Cms
No fix yet
HIGH 7.5
CVE-2019-15862
An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (eve…
Ckfinder
2.6.3+
HIGH 7.5
CVE-2019-16720
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by…
Zzzphp
No fix yet