Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 5.3 CVE-2018-19789 An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x be… Symfony 2.7.50 / 2.8.49+ Fix from $1,6002018-12-18 CRITICAL 9.6 CVE-2018-6152 The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome pri… Chrome 66.0.3359.106+ Fix from $2,3002018-12-04 MEDIUM 6.5 CVE-2018-16093 In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload… Xclarity Integrator 5.5+ Fix from $1,6002018-11-30 MEDIUM 6.5 CVE-2018-16097 LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system … Xclarity Integrator 3.5 / 5.5+ Fix from $1,6002018-11-30 HIGH 8.8 CVE-2018-15537EPSS 5% Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain access to the server via crafte… Ocsinventory Ng No fix yet Fix from $1,9502018-11-29 CRITICAL 9.8 CVE-2018-19692 An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploadin… Tp5cms after 2017-05-25 Fix from $2,3002018-11-29 CRITICAL 9.8 CVE-2018-17936EPSS 15% NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the serv… Nuuo Cms after 3.3 Fix from $2,3002018-11-27 HIGH 8.8 CVE-2018-19562 An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Prog… Phpok No fix yet Fix from $1,9502018-11-26 HIGH 8.8 CVE-2018-19550EPSS 6% Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can … Email Marketer after 6.1.6 Fix from $1,9502018-11-26 HIGH 7.2 CVE-2018-19537EPSS 6% TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuratio… Archer C5 Firmware after 2_160201_us Fix from $1,9502018-11-26 HIGH 7.2 CVE-2018-19457 Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faqimages with a .php file. Faq Script No fix yet Fix from $1,9502018-11-22 HIGH 7.2 CVE-2018-19422EPSS 64% /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits … Subrion Cms No fix yet Fix from $1,9502018-11-21 HIGH 7.2 CVE-2018-19423EPSS 18% Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file. Codiad No fix yet Fix from $1,9502018-11-21 HIGH 7.2 CVE-2018-19424 ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files. Clippercms Mitigation only Fix from $1,9502018-11-21 CRITICAL 9.6 CVE-2018-18563 An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number a… Accu Chek Inform Ii Firmware 03.01.03 / 03.01.06+ Fix from $2,3002018-11-20 MEDIUM 6.8 CVE-2018-18565 An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number a… Accu Chek Inform Ii Firmware 03.01.03 / 03.01.06+ Fix from $1,6002018-11-20 CRITICAL 9.8 CVE-2018-9209 Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2 Php Traditional Server after 1.2.2 Fix from $2,3002018-11-19 CRITICAL 9.8 CVE-2018-9207 Arbitrary file upload in jQuery Upload File <= 4.0.2 Jquery Upload File after 4.0.2 Fix from $2,3002018-11-19 CRITICAL 9.8 CVE-2018-19355 modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute … Prestashop after 1.7.0.0 Fix from $2,3002018-11-19 CRITICAL 9.8 CVE-2018-18793EPSS 10% School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. School Event Management System No fix yet Fix from $2,3002018-11-16 HIGH 8.8 CVE-2018-0686 Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers… Debun Imap after 3.3p_r4.0 Fix from $1,9502018-11-15 CRITICAL 9.8 CVE-2018-19126EPSS 23% PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload. Prestashop 1.6.1.23 / 1.7.4.4+ Fix from $2,3002018-11-09 CRITICAL 9.8 CVE-2018-9208 Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta Jquery Picture Cut No fix yet Fix from $2,3002018-11-05 CRITICAL 9.8 CVE-2018-18934 An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the … Popojicms No fix yet Fix from $2,3002018-11-05 HIGH 7.2 CVE-2018-18942 In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data… Basercms 4.1.4+ Fix from $1,9502018-11-05 HIGH 8.8 CVE-2018-1552 IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a m… Robotic Process Automation With Automation Anywhere Patch available Fix from $1,9502018-11-02 CRITICAL 9.8 CVE-2018-18888 An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files be… Laravelcms after 2018-04-02 Fix from $2,3002018-11-01 CRITICAL 9.8 CVE-2018-18874 nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Con… Nc Cms after 2017-03-10 Fix from $2,3002018-10-31 CRITICAL 9.8 CVE-2018-18830 An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login sta… Mcms Mitigation only Fix from $2,3002018-10-30 HIGH 7.5 CVE-2018-18771 An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by… Lulu Cms after 2015-05-14 Fix from $1,9502018-10-29