Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-9608
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider…
Ofcms
1.1.3+
HIGH 8.8
CVE-2019-9609
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider…
Ofcms
1.1.3+
HIGH 8.8
CVE-2019-9612
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider…
Ofcms
1.1.3+
HIGH 7.2
CVE-2019-9613
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider…
Ofcms
1.1.3+
HIGH 8.8
CVE-2019-9617
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider…
Ofcms
1.1.3+
HIGH 8.8
CVE-2019-9581EPSS 13%
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP…
Booked
Patch available
HIGH 7.2
CVE-2019-9572
SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with …
Schoolcms
No fix yet
HIGH 7.2
CVE-2019-9181
SchoolCMS version 2.3.1 allows file upload via the logo upload feature at admin.php?m=admin&c=site&a=save by using the .jpg extension, changing the C…
Schoolcms
No fix yet
HIGH 8.8
CVE-2018-20063
An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in t…
Testrail
Mitigation only
HIGH 7.2
CVE-2019-9050
An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive…
Pluck
No fix yet
HIGH 7.2
CVE-2019-9042
An issue was discovered in Sitemagic CMS v4.4. In the index.php?SMExt=SMFiles URI, the user can upload a .php file to execute arbitrary code, as demo…
Sitemagic Cms
No fix yet
HIGH 8.8
CVE-2019-8942EPSS 83%
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary …
WordPress
4.9.9+
HIGH 8.8
CVE-2019-8933
In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execu…
Dedecms
No fix yet
HIGH 7.5
CVE-2019-8433
JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.
Jtbc Php
No fix yet
MEDIUM 6.5
CVE-2019-8394 KEVEPSS 63%
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
Manageengine Servicedesk Plus
10.0.0+
HIGH 7.5
CVE-2019-8362
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=sa…
Dedecms
5.7+
CRITICAL 9.8
CVE-2019-0259
SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file for…
Businessobjects
Mitigation only
HIGH 7.5
CVE-2019-7721
lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters.
Nc Cms
No fix yet
CRITICAL 9.8
CVE-2019-7684
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.comm…
Inxedu
after 2018-12-24
CRITICAL 9.8
CVE-2019-6139
Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. Successful exploitation of th…
User Id
1.3.0+
HIGH 8.8
CVE-2019-0017
The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of maliciou…
Junos Space
Mitigation only
CRITICAL 9.9
CVE-2018-1969
IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the…
Security Identity Manager
after 6.0.0.20
HIGH 8.8
CVE-2018-16169
Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.
Remote Service Manager
after 3.1.0
HIGH 7.2
CVE-2019-5009EPSS 10%
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and …
Vtiger Crm
after 7.1.0
HIGH 8.8
CVE-2018-20166EPSS 7%
A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishan…
Rukovoditel
No fix yet
CRITICAL 9.8
CVE-2018-5204
ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote ar…
Ml Report
after 2.18.628.5980
MEDIUM 5.5
CVE-2018-15333
On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including Guest Role, to have access an…
Big Ip Local Traffic Manager
after 14.1.0
CRITICAL 9.8
CVE-2018-7836EPSS 32%
An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow uplo…
Iiot Monitor
Mitigation only
HIGH 8.8
CVE-2018-1000839
LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This atta…
Librehealth Ehr
No fix yet
HIGH 8.8
CVE-2018-1000811EPSS 48%
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Re…
Bludit
No fix yet