Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-11807
The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm …
Woocommerce Checkout Manager
4.3+
HIGH 8.8
CVE-2019-11615
/fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upl…
Doorgets Cms
No fix yet
HIGH 8.8
CVE-2019-11568
An issue was discovered in AikCms v2.0. There is a File upload vulnerability, as demonstrated by an admin/page/system/nav.php request with PHP code i…
Aikcms
No fix yet
HIGH 8.8
CVE-2019-8992
The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIB…
Activematrix Bpm
after 4.2.0
CRITICAL 9.8
CVE-2019-9951
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR21…
My Cloud Mirror Gen 2 Firmware
2.31.174+
HIGH 8.8
CVE-2019-11446EPSS 8%
An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files s…
Atutor
after 2.2.4
HIGH 8.8
CVE-2019-11447EPSS 52%
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via th…
Cutenews
No fix yet
HIGH 7.2
CVE-2019-11445EPSS 14%
OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory …
Openkm
6.3.7+
HIGH 7.2
CVE-2019-11401
A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted f…
Siteserver Cms
No fix yet
HIGH 8.8
CVE-2019-11377
wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according …
Wcms
No fix yet
CRITICAL 9.8
CVE-2019-11344
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-p…
Pluck
No fix yet
CRITICAL 9.8
CVE-2019-11223EPSS 9%
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by…
Supportcandy
after 2.0.0
HIGH 8.8
CVE-2018-19453
Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.
Xperience
11.0.45+
CRITICAL 9.9
CVE-2019-4013EPSS 14%
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in cod…
Bigfix Platform
after 9.5.11
CRITICAL 9.8
CVE-2019-3940
Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnera…
Webaccess
Mitigation only
HIGH 8.8
CVE-2019-11028
GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to the server via the "Document…
Web Module
1.40+
HIGH 7.2
CVE-2019-10478
An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. An unrestricted file upload vulnerability in the Front Circle Contro…
Rbw 100 Firmware
No fix yet
HIGH 7.5
CVE-2019-3489
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when co…
Content Manager
after 9.3
HIGH 7.2
CVE-2019-10652EPSS 7%
An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addo…
Flatcore
No fix yet
CRITICAL 9.8
CVE-2019-10647EPSS 7%
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage…
Zzzphp
No fix yet
CRITICAL 9.8
CVE-2019-10276
Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the im…
Razor
No fix yet
HIGH 7.5
CVE-2019-10012
Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archi…
Internet Campus Solution
2.1.4+
HIGH 8.8
CVE-2019-3495
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, all…
Unibox Firmware
No fix yet
CRITICAL 9.8
CVE-2018-20526EPSS 73%
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
Roxy Fileman
No fix yet
CRITICAL 9.8
CVE-2018-19514
In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authent…
Webgalamb
after 7.0
CRITICAL 9.8
CVE-2019-9825
FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowa…
Feifeicms
Mitigation only
MEDIUM 6.5
CVE-2019-9692EPSS 46%
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JP…
Cms Made Simple
2.2.10+
HIGH 8.8
CVE-2019-9185
Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a pr…
Bolt
3.6.5+
HIGH 7.2
CVE-2018-17418
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, bec…
Monstra
No fix yet
CRITICAL 9.8
CVE-2019-9623EPSS 8%
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.
Feng Office
No fix yet