Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2019-7274EPSS 29% Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root. Enterprise after 2.3.0a Fix from $2,3002019-07-01 HIGH 8.8 CVE-2019-7669EPSS 31% Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated atta… Flexair after 2.3.38 Fix from $1,9502019-07-01 CRITICAL 9.8 CVE-2019-13082 Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive befor… Chamilo Lms No fix yet Fix from $2,3002019-06-30 HIGH 7.5 CVE-2019-12744EPSS 12% SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-201… Seeddms 5.1.11+ Fix from $1,9502019-06-20 HIGH 7.2 CVE-2019-9842 madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFi… Miniblog after 2018-05-18 Fix from $1,9502019-06-14 CRITICAL 10.0 CVE-2019-10959 BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the lat… Alaris Gateway Workstation Firmware after 2.3.6 Fix from $2,3002019-06-13 CRITICAL 9.8 CVE-2019-7838EPSS 17% ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Succ… Coldfusion Mitigation only Fix from $2,3002019-06-12 HIGH 8.8 CVE-2019-4069 IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. … Intelligent Operations Center after 5.2.1.1 Fix from $1,9502019-06-07 HIGH 8.8 CVE-2019-9189EPSS 12% Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central … Flexair after 2.3.38 Fix from $1,9502019-06-05 HIGH 7.2 CVE-2019-1861 A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrar… Industrial Network Director 1.6.0+ Fix from $1,9502019-06-05 CRITICAL 9.8 CVE-2019-9642 An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP … Pydio after 8.2.2 Fix from $2,3002019-06-05 HIGH 8.8 CVE-2019-5357 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. Intelligent Management Center 7.3+ Fix from $1,9502019-06-05 CRITICAL 9.8 CVE-2019-11185 The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete pat… Live Chat 8.0.26+ Fix from $2,3002019-06-03 HIGH 8.8 CVE-2019-12548 Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajax/upload… Bludit 3.9.0+ Fix from $1,9502019-06-03 CRITICAL 9.8 CVE-2019-12377EPSS 6% A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows… Landesk Management Suite No fix yet Fix from $2,3002019-06-03 CRITICAL 9.8 CVE-2019-7816EPSS 68% ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Succes… Coldfusion Mitigation only Fix from $2,3002019-05-24 HIGH 7.2 CVE-2016-10751 osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an … Osclass Mitigation only Fix from $1,9502019-05-24 CRITICAL 9.8 CVE-2016-10752 serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensi… Serendipity Mitigation only Fix from $2,3002019-05-24 HIGH 8.8 CVE-2016-10758 PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_na… Phpkit No fix yet Fix from $1,9502019-05-24 HIGH 8.8 CVE-2018-19612 The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute… Dr 250 Firmware Mitigation only Fix from $1,9502019-05-24 CRITICAL 9.8 CVE-2019-12150 Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The att… Ultimateeditor No fix yet Fix from $2,3002019-05-24 MEDIUM 6.5 CVE-2017-11561 An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Ala… Manageengine Opmanager No fix yet Fix from $1,6002019-05-23 MEDIUM 5.4 CVE-2019-6513 An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing … Api Manager Mitigation only Fix from $1,6002019-05-21 HIGH 8.8 CVE-2019-12185EPSS 18% eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command exec… Elabftw No fix yet Fix from $1,9502019-05-20 HIGH 8.8 CVE-2019-12170EPSS 9% ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote … Atutor after 2.2.4 Fix from $1,9502019-05-17 CRITICAL 9.8 CVE-2019-11887 SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution. Simplybook after 2019-05-11 Fix from $2,3002019-05-17 HIGH 8.8 CVE-2019-12099EPSS 18% In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput… Php Fusion 9.03.00+ Fix from $1,9502019-05-14 MEDIUM 6.5 CVE-2019-8404EPSS 8% An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the cre… Webiness Inventory No fix yet Fix from $1,6002019-05-14 HIGH 8.1 CVE-2019-10869EPSS 8% Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This… Ninja Forms File Uploads 3.0.23+ Fix from $1,9502019-05-07 HIGH 8.8 CVE-2018-4063 KEVEPSS 28% An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially craf… Aleos 4.4.9 / 4.9.4+ Fix from $1,9502019-05-06