Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2015-9402 The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload. Users Ultra Membership 1.5.59+ Fix from $1,9502019-09-20 MEDIUM 6.5 CVE-2019-14916 An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file upload. Adas No fix yet Fix from $1,6002019-09-20 HIGH 7.2 CVE-2019-14252 An issue was discovered in the secure portal in Publisure 2.1.2. Once successfully authenticated as an administrator, one is able to inject arbitrary… Publisure No fix yet Fix from $1,9502019-09-18 HIGH 7.4 CVE-2019-15843 A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition involving a man-in-the-middle a… Xiaomi Millet Firmware Mitigation only Fix from $1,9502019-09-18 CRITICAL 9.8 CVE-2016-10995 The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php. Telvolution 2.3.0+ Fix from $2,3002019-09-18 HIGH 8.8 CVE-2019-6839 A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 … Meg6501 0001 Firmware 1.3.7+ Fix from $1,9502019-09-17 CRITICAL 9.8 CVE-2019-15131 In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploa… Code42 after 6.8.8 Fix from $2,3002019-09-17 HIGH 7.2 CVE-2019-8371 OpenEMR v5.0.1-6 allows code execution. Openemr No fix yet Fix from $1,9502019-09-16 HIGH 7.5 CVE-2016-10958 The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php. Estatik 2.3.0+ Fix from $1,9502019-09-16 MEDIUM 6.5 CVE-2016-10959 The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin… Estatik 2.3.1+ Fix from $1,6002019-09-16 HIGH 8.8 CVE-2019-16318 In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by … Pimcore 5.7.1+ Fix from $1,9502019-09-14 CRITICAL 9.8 CVE-2016-10954 The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload. Neosense 1.8+ Fix from $2,3002019-09-13 CRITICAL 9.8 CVE-2016-10955 The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking. Cysteme Finder 1.4+ Fix from $2,3002019-09-13 CRITICAL 9.8 CVE-2019-16192 upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module … Doccms No fix yet Fix from $2,3002019-09-09 HIGH 8.8 CVE-2019-16131EPSS 7% framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be writte… Oklite No fix yet Fix from $1,9502019-09-09 CRITICAL 9.8 CVE-2019-13187 The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fi… Rich Text Formatter after 1.1.1 Fix from $2,3002019-09-05 CRITICAL 9.8 CVE-2019-13976 eGain Chat 15.0.3 allows unrestricted file upload. Chat Mitigation only Fix from $2,3002019-09-04 HIGH 8.8 CVE-2019-15813EPSS 33% Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell. Sentrifugo No fix yet Fix from $1,9502019-09-04 HIGH 8.8 CVE-2019-15866 The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_ajax_crellyslider_importSlide… Crelly Slider 1.3.5+ Fix from $1,9502019-09-03 HIGH 7.5 CVE-2017-18592 The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads. Wc Catalog Enquiry 3.1.0+ Fix from $1,9502019-08-27 HIGH 8.8 CVE-2019-15649 The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload. Insert Or Embed Articulate Content 4.2999+ Fix from $1,9502019-08-27 CRITICAL 9.8 CVE-2019-15524 CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote … Csz Cms Mitigation only Fix from $2,3002019-08-26 HIGH 7.5 CVE-2015-9338 The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files. Wordpress File Upload 2.5.0+ Fix from $1,9502019-08-22 HIGH 7.5 CVE-2015-9339 The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files. Wordpress File Upload 2.7.1+ Fix from $1,9502019-08-22 HIGH 7.5 CVE-2015-9340 The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and… Wordpress File Upload 3.0.0+ Fix from $1,9502019-08-22 HIGH 7.5 CVE-2015-9341 The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files. Wordpress File Upload 3.4.1+ Fix from $1,9502019-08-22 CRITICAL 9.8 CVE-2019-11031 Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload fil… Mirasys Vms 7.6.1 / 8.3.2+ Fix from $2,3002019-08-22 HIGH 7.2 CVE-2018-18572 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP… Oscommerce Mitigation only Fix from $1,9502019-08-22 CRITICAL 9.8 CVE-2019-15091 filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload. Integria Ims Mitigation only Fix from $2,3002019-08-16 HIGH 8.8 CVE-2019-14755 The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type. Leaf Admin Mitigation only Fix from $1,9502019-08-15