Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-5395
A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.
3par Service Processor Firmware
5.0.5.1+
MEDIUM 5.4
CVE-2019-14748
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries.…
Osticket
1.10.7 / 1.12.1+
HIGH 7.2
CVE-2019-7930
A file upload restriction bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user…
Magento
2.1.18 / 2.2.9+
HIGH 7.2
CVE-2019-7912
A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by a…
Magento
2.1.18 / 2.2.9+
HIGH 7.5
CVE-2019-7861
Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento …
Magento
2.1.18 / 2.2.9+
HIGH 7.3
CVE-2017-18435
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 6.7
CVE-2018-20925
cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).
Cpanel
62.0.42 / 68.0.33+
MEDIUM 6.7
CVE-2018-20926
cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).
Cpanel
62.0.42 / 68.0.33+
HIGH 7.2
CVE-2019-3960
Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a …
Wallacepos
Patch available
HIGH 8.8
CVE-2015-5601
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
Edx Platform
2015-07-20+
HIGH 8.8
CVE-2019-10267EPSS 75%
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any direct…
Cloud Backup Suite
8.1.1.50+
HIGH 7.5
CVE-2019-1010209
GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthenticated/unzuthorized Attacker can upload executabl…
Gourl
after 1.4.13
HIGH 7.5
CVE-2019-1010123
MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a fi…
Modx Revolution
after 2.6.4
CRITICAL 9.8
CVE-2019-12326
Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated …
Sp R50p Firmware
No fix yet
HIGH 8.8
CVE-2019-13979
In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.
Directus 7 Api
2.2.1+
HIGH 8.8
CVE-2019-13980
In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote co…
Directus 7 Api
after 2.3.0
HIGH 8.8
CVE-2019-13984
Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded …
Directus 7 Api
2.3.0+
CRITICAL 9.8
CVE-2019-13973
LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.
Layerbb
No fix yet
HIGH 7.5
CVE-2019-13359EPSS 26%
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp …
Webpanel
No fix yet
CRITICAL 9.8
CVE-2019-1010062
PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The component is: da…
Pluckcms
after 4.7.4
HIGH 7.5
CVE-2019-10930
A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication …
Digsi 5 Engineering Software
Mitigation only
HIGH 7.2
CVE-2019-10935
A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19)…
Simatic Pcs 7
after 7.2
HIGH 7.2
CVE-2019-0327
SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.8
CVE-2019-12803
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an att…
I Onenet
after 4.0.16
HIGH 7.5
CVE-2019-13464
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads ru…
Owasp Modsecurity Core Rule Set
Patch available
CRITICAL 9.8
CVE-2019-12971
BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.
Bks Ebk Ethernet Buskoppler Pro Firmware
3.01+
CRITICAL 9.8
CVE-2019-13294EPSS 19%
AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthentic…
School Erp
No fix yet
CRITICAL 10.0
CVE-2019-7257EPSS 70%
Linear eMerge E3-Series devices allow Unrestricted File Upload.
Linear Emerge Essential Firmware
after 1.00-06
CRITICAL 10.0
CVE-2019-7268EPSS 6%
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
Linear Emerge 50p Firmware
after 4.6.07
HIGH 8.8
CVE-2019-4292
IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the v…
Security Guardium
Patch available