Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.5 CVE-2019-11807 The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm … Woocommerce Checkout Manager 4.3+ Fix from $1,9502019-05-06 HIGH 8.8 CVE-2019-11615 /fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upl… Doorgets Cms No fix yet Fix from $1,9502019-04-30 HIGH 8.8 CVE-2019-11568 An issue was discovered in AikCms v2.0. There is a File upload vulnerability, as demonstrated by an admin/page/system/nav.php request with PHP code i… Aikcms No fix yet Fix from $1,9502019-04-27 HIGH 8.8 CVE-2019-8992 The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIB… Activematrix Bpm after 4.2.0 Fix from $1,9502019-04-24 CRITICAL 9.8 CVE-2019-9951 Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR21… My Cloud Mirror Gen 2 Firmware 2.31.174+ Fix from $2,3002019-04-24 HIGH 8.8 CVE-2019-11446EPSS 8% An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files s… Atutor after 2.2.4 Fix from $1,9502019-04-22 HIGH 8.8 CVE-2019-11447EPSS 52% An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via th… Cutenews No fix yet Fix from $1,9502019-04-22 HIGH 7.2 CVE-2019-11445EPSS 14% OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory … Openkm 6.3.7+ Fix from $1,9502019-04-22 HIGH 7.2 CVE-2019-11401 A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted f… Siteserver Cms No fix yet Fix from $1,9502019-04-22 HIGH 8.8 CVE-2019-11377 wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according … Wcms No fix yet Fix from $1,9502019-04-20 CRITICAL 9.8 CVE-2019-11344 data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-p… Pluck No fix yet Fix from $2,3002019-04-19 CRITICAL 9.8 CVE-2019-11223EPSS 9% An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by… Supportcandy after 2.0.0 Fix from $2,3002019-04-18 HIGH 8.8 CVE-2018-19453 Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type. Xperience 11.0.45+ Fix from $1,9502019-04-10 CRITICAL 9.9 CVE-2019-4013EPSS 14% IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in cod… Bigfix Platform after 9.5.11 Fix from $2,3002019-04-10 CRITICAL 9.8 CVE-2019-3940 Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnera… Webaccess Mitigation only Fix from $2,3002019-04-09 HIGH 8.8 CVE-2019-11028 GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to the server via the "Document… Web Module 1.40+ Fix from $1,9502019-04-09 HIGH 7.2 CVE-2019-10478 An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. An unrestricted file upload vulnerability in the Front Circle Contro… Rbw 100 Firmware No fix yet Fix from $1,9502019-04-05 HIGH 7.5 CVE-2019-3489 An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when co… Content Manager after 9.3 Fix from $1,9502019-04-01 HIGH 7.2 CVE-2019-10652EPSS 7% An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addo… Flatcore No fix yet Fix from $1,9502019-03-30 CRITICAL 9.8 CVE-2019-10647EPSS 7% ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage… Zzzphp No fix yet Fix from $2,3002019-03-30 CRITICAL 9.8 CVE-2019-10276 Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the im… Razor No fix yet Fix from $2,3002019-03-29 HIGH 7.5 CVE-2019-10012 Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archi… Internet Campus Solution 2.1.4+ Fix from $1,9502019-03-25 HIGH 8.8 CVE-2019-3495 An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, all… Unibox Firmware No fix yet Fix from $1,9502019-03-21 CRITICAL 9.8 CVE-2018-20526EPSS 73% Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. Roxy Fileman No fix yet Fix from $2,3002019-03-21 CRITICAL 9.8 CVE-2018-19514 In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authent… Webgalamb after 7.0 Fix from $2,3002019-03-21 CRITICAL 9.8 CVE-2019-9825 FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowa… Feifeicms Mitigation only Fix from $2,3002019-03-14 MEDIUM 6.5 CVE-2019-9692EPSS 46% class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JP… Cms Made Simple 2.2.10+ Fix from $1,6002019-03-11 HIGH 8.8 CVE-2019-9185 Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a pr… Bolt 3.6.5+ Fix from $1,9502019-03-07 HIGH 7.2 CVE-2018-17418 Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, bec… Monstra No fix yet Fix from $1,9502019-03-07 CRITICAL 9.8 CVE-2019-9623EPSS 8% Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php. Feng Office No fix yet Fix from $2,3002019-03-07