Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2019-9608 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 8.8 CVE-2019-9609 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 8.8 CVE-2019-9612 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 7.2 CVE-2019-9613 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 8.8 CVE-2019-9617 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 8.8 CVE-2019-9581EPSS 13% phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP… Booked Patch available Fix from $1,9502019-03-06 HIGH 7.2 CVE-2019-9572 SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with … Schoolcms No fix yet Fix from $1,9502019-03-05 HIGH 7.2 CVE-2019-9181 SchoolCMS version 2.3.1 allows file upload via the logo upload feature at admin.php?m=admin&c=site&a=save by using the .jpg extension, changing the C… Schoolcms No fix yet Fix from $1,9502019-02-26 HIGH 8.8 CVE-2018-20063 An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in t… Testrail Mitigation only Fix from $1,9502019-02-25 HIGH 7.2 CVE-2019-9050 An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive… Pluck No fix yet Fix from $1,9502019-02-23 HIGH 7.2 CVE-2019-9042 An issue was discovered in Sitemagic CMS v4.4. In the index.php?SMExt=SMFiles URI, the user can upload a .php file to execute arbitrary code, as demo… Sitemagic Cms No fix yet Fix from $1,9502019-02-23 HIGH 8.8 CVE-2019-8942EPSS 83% WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary … WordPress 4.9.9+ Fix from $1,9502019-02-20 HIGH 8.8 CVE-2019-8933 In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execu… Dedecms No fix yet Fix from $1,9502019-02-19 HIGH 7.5 CVE-2019-8433 JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file. Jtbc Php No fix yet Fix from $1,9502019-02-18 MEDIUM 6.5 CVE-2019-8394 KEVEPSS 63% Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. Manageengine Servicedesk Plus 10.0.0+ Fix from $1,6002019-02-17 HIGH 7.5 CVE-2019-8362 DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=sa… Dedecms 5.7+ Fix from $1,9502019-02-16 CRITICAL 9.8 CVE-2019-0259 SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file for… Businessobjects Mitigation only Fix from $2,3002019-02-15 HIGH 7.5 CVE-2019-7721 lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters. Nc Cms No fix yet Fix from $1,9502019-02-11 CRITICAL 9.8 CVE-2019-7684 inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.comm… Inxedu after 2018-12-24 Fix from $2,3002019-02-09 CRITICAL 9.8 CVE-2019-6139 Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. Successful exploitation of th… User Id 1.3.0+ Fix from $2,3002019-02-07 HIGH 8.8 CVE-2019-0017 The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of maliciou… Junos Space Mitigation only Fix from $1,9502019-01-15 CRITICAL 9.9 CVE-2018-1969 IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the… Security Identity Manager after 6.0.0.20 Fix from $2,3002019-01-14 HIGH 8.8 CVE-2018-16169 Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors. Remote Service Manager after 3.1.0 Fix from $1,9502019-01-09 HIGH 7.2 CVE-2019-5009EPSS 10% Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and … Vtiger Crm after 7.1.0 Fix from $1,9502019-01-04 HIGH 8.8 CVE-2018-20166EPSS 7% A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishan… Rukovoditel No fix yet Fix from $1,9502019-01-02 CRITICAL 9.8 CVE-2018-5204 ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote ar… Ml Report after 2.18.628.5980 Fix from $2,3002018-12-28 MEDIUM 5.5 CVE-2018-15333 On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including Guest Role, to have access an… Big Ip Local Traffic Manager after 14.1.0 Fix from $1,6002018-12-28 CRITICAL 9.8 CVE-2018-7836EPSS 32% An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow uplo… Iiot Monitor Mitigation only Fix from $2,3002018-12-24 HIGH 8.8 CVE-2018-1000839 LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This atta… Librehealth Ehr No fix yet Fix from $1,9502018-12-20 HIGH 8.8 CVE-2018-1000811EPSS 48% bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Re… Bludit No fix yet Fix from $1,9502018-12-20