Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2018-18752 Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo paramete… Webiness Inventory No fix yet Fix from $2,3002018-10-29 CRITICAL 9.8 CVE-2018-18475EPSS 20% Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload. Manageengine Opmanager No fix yet Fix from $2,3002018-10-23 HIGH 8.8 CVE-2018-18382 Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Updat… Advanced Hrm No fix yet Fix from $1,9502018-10-16 HIGH 7.5 CVE-2018-18315 com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils on… Lemon Mitigation only Fix from $1,9502018-10-15 CRITICAL 9.8 CVE-2018-9206EPSS 97% Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 Jquery File Upload after 9.22.0 Fix from $2,3002018-10-11 HIGH 8.8 CVE-2018-18086 EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users. Empirecms No fix yet Fix from $1,9502018-10-09 HIGH 8.8 CVE-2018-17442EPSS 14% An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endp… Central Wifimanager 1.03+ Fix from $1,9502018-10-08 CRITICAL 9.8 CVE-2018-17440EPSS 38% An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and ha… Central Wifimanager 1.03+ Fix from $2,3002018-10-08 CRITICAL 9.8 CVE-2015-9271 The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/v… Video Conference No fix yet Fix from $2,3002018-10-04 HIGH 8.8 CVE-2018-17553EPSS 79% An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authen… Navigate Cms Patch available Fix from $1,9502018-10-03 CRITICAL 9.8 CVE-2018-17573 The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fck… Wp Insert after 2.4.2 Fix from $2,3002018-09-28 HIGH 7.5 CVE-2018-17055 An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads. Sitefinity after 11.0 Fix from $1,9502018-09-28 CRITICAL 9.8 CVE-2018-15961 KEVEPSS 100% Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnera… Coldfusion Mitigation only Fix from $2,3002018-09-25 MEDIUM 5.3 CVE-2018-16821 SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests. Seacms No fix yet Fix from $1,6002018-09-21 HIGH 8.8 CVE-2018-17139 UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php… Ultimatepos No fix yet Fix from $1,9502018-09-17 CRITICAL 9.8 CVE-2018-16287EPSS 20% LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs. Supersign Cms No fix yet Fix from $2,3002018-09-14 HIGH 8.8 CVE-2018-16796 HiScout GRC Suite before 3.1.5 allows Unrestricted Upload of Files with Dangerous Types. Grc Suite 3.1.5+ Fix from $1,9502018-09-13 CRITICAL 9.8 CVE-2018-16974 An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filema… Elefant 2.0.7+ Fix from $2,3002018-09-12 HIGH 7.2 CVE-2018-16388 e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg … E107 Patch available Fix from $1,9502018-09-12 CRITICAL 9.8 CVE-2018-16731 CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .… Cscms No fix yet Fix from $2,3002018-09-08 CRITICAL 9.8 CVE-2018-0645 MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors. Mtappjquery after 1.8.1 Fix from $2,3002018-09-07 HIGH 8.8 CVE-2018-1000658 LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution… Limesurvey 3.14.4+ Fix from $1,9502018-09-06 CRITICAL 9.8 CVE-2018-16370 In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP… Pescms Team No fix yet Fix from $2,3002018-09-03 CRITICAL 9.8 CVE-2018-16352 There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png c… Weaselcms No fix yet Fix from $2,3002018-09-02 CRITICAL 9.8 CVE-2018-15882 An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the… Joomla\! 3.8.12+ Fix from $2,3002018-08-29 CRITICAL 9.8 CVE-2014-10074 Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the up… Umbraco Cms 7.2.0+ Fix from $2,3002018-08-27 CRITICAL 9.8 CVE-2015-9263EPSS 12% An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbi… Uptime Infrastructure Monitor No fix yet Fix from $2,3002018-08-27 CRITICAL 9.0 CVE-2018-3832 An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows for uploading arbitrary MPFS… Hub 2245 222 Firmware Mitigation only Fix from $2,3002018-08-23 HIGH 8.8 CVE-2018-1000646 LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write fi… Librehealth Ehr No fix yet Fix from $1,9502018-08-20 HIGH 8.8 CVE-2018-15573 An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on d… Reprise License Manager 16.1+ Fix from $1,9502018-08-20