Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-7274EPSS 29%
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
Enterprise
after 2.3.0a
HIGH 8.8
CVE-2019-7669EPSS 31%
Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated atta…
Flexair
after 2.3.38
CRITICAL 9.8
CVE-2019-13082
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive befor…
Chamilo Lms
No fix yet
HIGH 7.5
CVE-2019-12744EPSS 12%
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-201…
Seeddms
5.1.11+
HIGH 7.2
CVE-2019-9842
madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFi…
Miniblog
after 2018-05-18
CRITICAL 10.0
CVE-2019-10959
BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the lat…
Alaris Gateway Workstation Firmware
after 2.3.6
CRITICAL 9.8
CVE-2019-7838EPSS 17%
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Succ…
Coldfusion
Mitigation only
HIGH 8.8
CVE-2019-4069
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. …
Intelligent Operations Center
after 5.2.1.1
HIGH 8.8
CVE-2019-9189EPSS 12%
Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central …
Flexair
after 2.3.38
HIGH 7.2
CVE-2019-1861
A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrar…
Industrial Network Director
1.6.0+
CRITICAL 9.8
CVE-2019-9642
An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP …
Pydio
after 8.2.2
HIGH 8.8
CVE-2019-5357
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Intelligent Management Center
7.3+
CRITICAL 9.8
CVE-2019-11185
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete pat…
Live Chat
8.0.26+
HIGH 8.8
CVE-2019-12548
Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajax/upload…
Bludit
3.9.0+
CRITICAL 9.8
CVE-2019-12377EPSS 6%
A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows…
Landesk Management Suite
No fix yet
CRITICAL 9.8
CVE-2019-7816EPSS 68%
ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Succes…
Coldfusion
Mitigation only
HIGH 7.2
CVE-2016-10751
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an …
Osclass
Mitigation only
CRITICAL 9.8
CVE-2016-10752
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensi…
Serendipity
Mitigation only
HIGH 8.8
CVE-2016-10758
PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_na…
Phpkit
No fix yet
HIGH 8.8
CVE-2018-19612
The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute…
Dr 250 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-12150
Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The att…
Ultimateeditor
No fix yet
MEDIUM 6.5
CVE-2017-11561
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Ala…
Manageengine Opmanager
No fix yet
MEDIUM 5.4
CVE-2019-6513
An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing …
Api Manager
Mitigation only
HIGH 8.8
CVE-2019-12185EPSS 18%
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command exec…
Elabftw
No fix yet
HIGH 8.8
CVE-2019-12170EPSS 9%
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote …
Atutor
after 2.2.4
CRITICAL 9.8
CVE-2019-11887
SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution.
Simplybook
after 2019-05-11
HIGH 8.8
CVE-2019-12099EPSS 18%
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput…
Php Fusion
9.03.00+
MEDIUM 6.5
CVE-2019-8404EPSS 8%
An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the cre…
Webiness Inventory
No fix yet
HIGH 8.1
CVE-2019-10869EPSS 8%
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This…
Ninja Forms File Uploads
3.0.23+
HIGH 8.8
CVE-2018-4063 KEVEPSS 28%
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially craf…
Aleos
4.4.9 / 4.9.4+