Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-18752
Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo paramete…
Webiness Inventory
No fix yet
CRITICAL 9.8
CVE-2018-18475EPSS 20%
Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.
Manageengine Opmanager
No fix yet
HIGH 8.8
CVE-2018-18382
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Updat…
Advanced Hrm
No fix yet
HIGH 7.5
CVE-2018-18315
com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils on…
Lemon
Mitigation only
CRITICAL 9.8
CVE-2018-9206EPSS 97%
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
Jquery File Upload
after 9.22.0
HIGH 8.8
CVE-2018-18086
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
Empirecms
No fix yet
HIGH 8.8
CVE-2018-17442EPSS 14%
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endp…
Central Wifimanager
1.03+
CRITICAL 9.8
CVE-2018-17440EPSS 38%
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and ha…
Central Wifimanager
1.03+
CRITICAL 9.8
CVE-2015-9271
The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/v…
Video Conference
No fix yet
HIGH 8.8
CVE-2018-17553EPSS 79%
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authen…
Navigate Cms
Patch available
CRITICAL 9.8
CVE-2018-17573
The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fck…
Wp Insert
after 2.4.2
HIGH 7.5
CVE-2018-17055
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
Sitefinity
after 11.0
CRITICAL 9.8
CVE-2018-15961 KEVEPSS 100%
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnera…
Coldfusion
Mitigation only
MEDIUM 5.3
CVE-2018-16821
SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.
Seacms
No fix yet
HIGH 8.8
CVE-2018-17139
UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php…
Ultimatepos
No fix yet
CRITICAL 9.8
CVE-2018-16287EPSS 20%
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
Supersign Cms
No fix yet
HIGH 8.8
CVE-2018-16796
HiScout GRC Suite before 3.1.5 allows Unrestricted Upload of Files with Dangerous Types.
Grc Suite
3.1.5+
CRITICAL 9.8
CVE-2018-16974
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filema…
Elefant
2.0.7+
HIGH 7.2
CVE-2018-16388
e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg …
E107
Patch available
CRITICAL 9.8
CVE-2018-16731
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .…
Cscms
No fix yet
CRITICAL 9.8
CVE-2018-0645
MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors.
Mtappjquery
after 1.8.1
HIGH 8.8
CVE-2018-1000658
LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution…
Limesurvey
3.14.4+
CRITICAL 9.8
CVE-2018-16370
In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP…
Pescms Team
No fix yet
CRITICAL 9.8
CVE-2018-16352
There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png c…
Weaselcms
No fix yet
CRITICAL 9.8
CVE-2018-15882
An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the…
Joomla\!
3.8.12+
CRITICAL 9.8
CVE-2014-10074
Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the up…
Umbraco Cms
7.2.0+
CRITICAL 9.8
CVE-2015-9263EPSS 12%
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbi…
Uptime Infrastructure Monitor
No fix yet
CRITICAL 9.0
CVE-2018-3832
An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows for uploading arbitrary MPFS…
Hub 2245 222 Firmware
Mitigation only
HIGH 8.8
CVE-2018-1000646
LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write fi…
Librehealth Ehr
No fix yet
HIGH 8.8
CVE-2018-15573
An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on d…
Reprise License Manager
16.1+