Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2018-19789
An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x be…
Symfony
2.7.50 / 2.8.49+
CRITICAL 9.6
CVE-2018-6152
The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome pri…
Chrome
66.0.3359.106+
MEDIUM 6.5
CVE-2018-16093
In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload…
Xclarity Integrator
5.5+
MEDIUM 6.5
CVE-2018-16097
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system …
Xclarity Integrator
3.5 / 5.5+
HIGH 8.8
CVE-2018-15537EPSS 5%
Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain access to the server via crafte…
Ocsinventory Ng
No fix yet
CRITICAL 9.8
CVE-2018-19692
An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploadin…
Tp5cms
after 2017-05-25
CRITICAL 9.8
CVE-2018-17936EPSS 15%
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the serv…
Nuuo Cms
after 3.3
HIGH 8.8
CVE-2018-19562
An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Prog…
Phpok
No fix yet
HIGH 8.8
CVE-2018-19550EPSS 6%
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can …
Email Marketer
after 6.1.6
HIGH 7.2
CVE-2018-19537EPSS 6%
TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuratio…
Archer C5 Firmware
after 2_160201_us
HIGH 7.2
CVE-2018-19457
Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faqimages with a .php file.
Faq Script
No fix yet
HIGH 7.2
CVE-2018-19422EPSS 64%
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits …
Subrion Cms
No fix yet
HIGH 7.2
CVE-2018-19423EPSS 18%
Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
Codiad
No fix yet
HIGH 7.2
CVE-2018-19424
ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.
Clippercms
Mitigation only
CRITICAL 9.6
CVE-2018-18563
An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number a…
Accu Chek Inform Ii Firmware
03.01.03 / 03.01.06+
MEDIUM 6.8
CVE-2018-18565
An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number a…
Accu Chek Inform Ii Firmware
03.01.03 / 03.01.06+
CRITICAL 9.8
CVE-2018-9209
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
Php Traditional Server
after 1.2.2
CRITICAL 9.8
CVE-2018-9207
Arbitrary file upload in jQuery Upload File <= 4.0.2
Jquery Upload File
after 4.0.2
CRITICAL 9.8
CVE-2018-19355
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute …
Prestashop
after 1.7.0.0
CRITICAL 9.8
CVE-2018-18793EPSS 10%
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
School Event Management System
No fix yet
HIGH 8.8
CVE-2018-0686
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers…
Debun Imap
after 3.3p_r4.0
CRITICAL 9.8
CVE-2018-19126EPSS 23%
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.
Prestashop
1.6.1.23 / 1.7.4.4+
CRITICAL 9.8
CVE-2018-9208
Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta
Jquery Picture Cut
No fix yet
CRITICAL 9.8
CVE-2018-18934
An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the …
Popojicms
No fix yet
HIGH 7.2
CVE-2018-18942
In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data…
Basercms
4.1.4+
HIGH 8.8
CVE-2018-1552
IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a m…
Robotic Process Automation With Automation Anywhere
Patch available
CRITICAL 9.8
CVE-2018-18888
An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files be…
Laravelcms
after 2018-04-02
CRITICAL 9.8
CVE-2018-18874
nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Con…
Nc Cms
after 2017-03-10
CRITICAL 9.8
CVE-2018-18830
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login sta…
Mcms
Mitigation only
HIGH 7.5
CVE-2018-18771
An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by…
Lulu Cms
after 2015-05-14